{
  "CVE_data_type" : "CVE",
  "CVE_data_format" : "MITRE",
  "CVE_data_version" : "4.0",
  "CVE_data_numberOfCVEs" : "7134",
  "CVE_data_timestamp" : "2020-08-29T09:00Z",
  "CVE_Items" : [ {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0001",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "office",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2000",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2003",
                    "version_affected" : "="
                  }, {
                    "version_value" : "xp",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "publisher",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2000",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2002",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2003",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/21863",
          "name" : "21863",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/1548",
          "name" : "1548",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1016825",
          "name" : "1016825",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.computerterrorism.com/research/ct12-09-2006-2.htm",
          "name" : "http://www.computerterrorism.com/research/ct12-09-2006-2.htm",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/406236",
          "name" : "VU#406236",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/445824/100/0/threaded",
          "name" : "20060912 Computer Terrorism (UK) :: Incident Response Centre - Microsoft Publisher Font Parsing Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/446630/100/100/threaded",
          "name" : "SSRT061187",
          "refsource" : "HP",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/19951",
          "name" : "19951",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA06-255A.html",
          "name" : "TA06-255A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/3565",
          "name" : "ADV-2006-3565",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-054",
          "name" : "MS06-054",
          "refsource" : "MS",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/28648",
          "name" : "publisher-pub-code-execution(28648)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A590",
          "name" : "oval:org.mitre.oval:def:590",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Stack-based buffer overflow in Microsoft Publisher 2000 through 2003 allows user-assisted remote attackers to execute arbitrary code via a crafted PUB file, which causes an overflow when parsing fonts."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:2000:sp3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:2003:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:2003:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:xp:sp3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:publisher:2000:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:publisher:2002:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:publisher:2003:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2006-09-12T23:07Z",
    "lastModifiedDate" : "2018-10-19T15:41Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0002",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "exchange_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2000",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "office",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2000",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2003",
                    "version_affected" : "="
                  }, {
                    "version_value" : "xp",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "outlook",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2000",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2002",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2003",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18368",
          "name" : "18368",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Third Party Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/330",
          "name" : "330",
          "refsource" : "SREASON",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/331",
          "name" : "331",
          "refsource" : "SREASON",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1015460",
          "name" : "1015460",
          "refsource" : "SECTRACK",
          "tags" : [ "Patch", "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://securitytracker.com/id?1015461",
          "name" : "1015461",
          "refsource" : "SECTRACK",
          "tags" : [ "Patch", "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://support.avaya.com/elmodocs2/security/ASA-2006-004.htm",
          "name" : "http://support.avaya.com/elmodocs2/security/ASA-2006-004.htm",
          "refsource" : "CONFIRM",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/252146",
          "name" : "VU#252146",
          "refsource" : "CERT-VN",
          "tags" : [ "Third Party Advisory", "US Government Resource" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/421518/100/0/threaded",
          "name" : "20060110 Microsoft Exchange Critical Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/421520/100/0/threaded",
          "name" : "20060110 Microsoft Outlook Critical Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16197",
          "name" : "16197",
          "refsource" : "BID",
          "tags" : [ "Patch", "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA06-010A.html",
          "name" : "TA06-010A",
          "refsource" : "CERT",
          "tags" : [ "Patch", "Third Party Advisory", "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0119",
          "name" : "ADV-2006-0119",
          "refsource" : "VUPEN",
          "tags" : [ "Permissions Required" ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-003",
          "name" : "MS06-003",
          "refsource" : "MS",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/22878",
          "name" : "win-tnef-overflow(22878)",
          "refsource" : "XF",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1082",
          "name" : "oval:org.mitre.oval:def:1082",
          "refsource" : "OVAL",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1165",
          "name" : "oval:org.mitre.oval:def:1165",
          "refsource" : "OVAL",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1316",
          "name" : "oval:org.mitre.oval:def:1316",
          "refsource" : "OVAL",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1456",
          "name" : "oval:org.mitre.oval:def:1456",
          "refsource" : "OVAL",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1485",
          "name" : "oval:org.mitre.oval:def:1485",
          "refsource" : "OVAL",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A624",
          "name" : "oval:org.mitre.oval:def:624",
          "refsource" : "OVAL",
          "tags" : [ "Third Party Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in Microsoft Outlook 2000 through 2003, Exchange 5.0 Server SP2 and 5.5 SP4, Exchange 2000 SP3, and Office allows remote attackers to execute arbitrary code via an e-mail message with a crafted Transport Neutral Encapsulation Format (TNEF) MIME attachment, related to message length validation."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:exchange_server:5.0:-:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:exchange_server:5.0:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:exchange_server:5.0:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:exchange_server:5.5:-:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:exchange_server:5.5:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:exchange_server:5.5:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:exchange_server:5.5:sp3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:exchange_server:5.5:sp4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:exchange_server:2000:sp3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:2000:sp3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:2003:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:2003:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:xp:sp3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:outlook:2000:sp3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:outlook:2002:sp3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:outlook:2003:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-10T22:03Z",
    "lastModifiedDate" : "2020-04-09T13:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0003",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "data_access_components",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.8",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/19583",
          "name" : "19583",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/20719",
          "name" : "20719",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1015894",
          "name" : "1015894",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.hitachi-support.com/security_e/vuls_e/HS06-013_e/01-e.html",
          "name" : "http://www.hitachi-support.com/security_e/vuls_e/HS06-013_e/01-e.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.hitachi-support.com/security_e/vuls_e/HS06-013_e/index-e.html",
          "name" : "http://www.hitachi-support.com/security_e/vuls_e/HS06-013_e/index-e.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/234812",
          "name" : "VU#234812",
          "refsource" : "CERT-VN",
          "tags" : [ "Third Party Advisory", "US Government Resource" ]
        }, {
          "url" : "http://www.osvdb.org/24517",
          "name" : "24517",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/475104/100/100/threaded",
          "name" : "20070729 Exploit In Internet Explorer",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/475108/100/100/threaded",
          "name" : "20070730 Re: Exploit In Internet Explorer",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/475118/100/100/threaded",
          "name" : "20070730 RE: Exploit In Internet Explorer",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/475490/100/100/threaded",
          "name" : "20070731 Re: Exploit In Internet Explorer",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/487216/100/200/threaded",
          "name" : "20080128 Exploit in IE6,7",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/487219/100/200/threaded",
          "name" : "20080128 Re: Exploit in IE6,7",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/17462",
          "name" : "17462",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/20797",
          "name" : "20797",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/data/vulnerabilities/exploits/0day_ie.pdf",
          "name" : "http://www.securityfocus.com/data/vulnerabilities/exploits/0day_ie.pdf",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA06-101A.html",
          "name" : "TA06-101A",
          "refsource" : "CERT",
          "tags" : [ "Third Party Advisory", "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/1319",
          "name" : "ADV-2006-1319",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/2452",
          "name" : "ADV-2006-2452",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-014",
          "name" : "MS06-014",
          "refsource" : "MS",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/25006",
          "name" : "mdac-rdsdataspace-execute-code(25006)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/29915",
          "name" : "ie-wscriptshell-command-execution(29915)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1204",
          "name" : "oval:org.mitre.oval:def:1204",
          "refsource" : "OVAL",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1323",
          "name" : "oval:org.mitre.oval:def:1323",
          "refsource" : "OVAL",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1511",
          "name" : "oval:org.mitre.oval:def:1511",
          "refsource" : "OVAL",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1742",
          "name" : "oval:org.mitre.oval:def:1742",
          "refsource" : "OVAL",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1778",
          "name" : "oval:org.mitre.oval:def:1778",
          "refsource" : "OVAL",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/2052",
          "name" : "2052",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/2164",
          "name" : "2164",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the RDS.Dataspace ActiveX control, which is contained in ActiveX Data Objects (ADO) and distributed in Microsoft Data Access Components (MDAC) 2.7 and 2.8, allows remote attackers to execute arbitrary code via unknown attack vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:data_access_components:2.5:sp3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:data_access_components:2.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:data_access_components:2.7:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:data_access_components:2.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:data_access_components:2.8:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:data_access_components:2.8:sp2:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:H/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "HIGH",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.1
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 4.9,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2006-04-12T00:02Z",
    "lastModifiedDate" : "2018-10-19T15:41Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0004",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "office",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2000",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18865",
          "name" : "18865",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1015632",
          "name" : "1015632",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/963628",
          "name" : "VU#963628",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16634",
          "name" : "16634",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0579",
          "name" : "ADV-2006-0579",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-010",
          "name" : "MS06-010",
          "refsource" : "MS",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24490",
          "name" : "powerpoint-tiff-information-disclosure(24490)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1555",
          "name" : "oval:org.mitre.oval:def:1555",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Microsoft PowerPoint 2000 in Office 2000 SP3 has an interaction with Internet Explorer that allows remote attackers to obtain sensitive information via a PowerPoint presentation that attempts to access objects in the Temporary Internet Files Folder (TIFF)."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:2000:sp3:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-14T20:02Z",
    "lastModifiedDate" : "2018-10-12T21:38Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0005",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "windows-nt",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "datacenter_server",
                    "version_affected" : "="
                  }, {
                    "version_value" : "xp",
                    "version_affected" : "="
                  }, {
                    "version_value" : "xp_tablet_pc",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_2000",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  }, {
                    "version_value" : "-",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_2000_advanced_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  }, {
                    "version_value" : "sp1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "sp2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "sp3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "sp4",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_2003_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "datacenter_edition",
                    "version_affected" : "="
                  }, {
                    "version_value" : "datacenter_edition_64-bit",
                    "version_affected" : "="
                  }, {
                    "version_value" : "enterprise_edition",
                    "version_affected" : "="
                  }, {
                    "version_value" : "enterprise_edition_64-bit",
                    "version_affected" : "="
                  }, {
                    "version_value" : "standard",
                    "version_affected" : "="
                  }, {
                    "version_value" : "standard_64-bit",
                    "version_affected" : "="
                  }, {
                    "version_value" : "web_edition",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_server_2000",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "none",
                    "version_affected" : "="
                  }, {
                    "version_value" : "sp1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "sp2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "sp3",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_server_2003",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "datacenter_sp1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "enterprise_sp1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "standard_sp1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "web_edition_sp1",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_xp",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  }, {
                    "version_value" : "-",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18852",
          "name" : "18852",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1015628",
          "name" : "1015628",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.idefense.com/intelligence/vulnerabilities/display.php?id=393",
          "name" : "20060214 Microsoft Windows Media Player Plugin Buffer Overflow Vulnerability",
          "refsource" : "IDEFENSE",
          "tags" : [ ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/692060",
          "name" : "VU#692060",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16644",
          "name" : "16644",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA06-045A.html",
          "name" : "TA06-045A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0575",
          "name" : "ADV-2006-0575",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-006",
          "name" : "MS06-006",
          "refsource" : "MS",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24493",
          "name" : "win-mediaplayer-plugin-embed-bo(24493)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1559",
          "name" : "oval:org.mitre.oval:def:1559",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Buffer overflow in the plug-in for Microsoft Windows Media Player (WMP) 9 and 10, when used in browsers other than Internet Explorer and set as the default application to handle media files, allows remote attackers to execute arbitrary code via HTML with an EMBED element containing a long src attribute."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows-nt:datacenter_server:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows-nt:datacenter_server:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows-nt:datacenter_server:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows-nt:datacenter_server:sp3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows-nt:datacenter_server:sp4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows-nt:xp:sp2:home:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows-nt:xp_tablet_pc:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows-nt:xp_tablet_pc:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows-nt:xp_tablet_pc:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2000:*:sp1:pro:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2000:*:sp2:pro:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2000:*:sp3:pro:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2000:*:sp4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2000:*:sp4:pro:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2000:-:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2000_advanced_server:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2000_advanced_server:sp1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2000_advanced_server:sp2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2000_advanced_server:sp3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2000_advanced_server:sp4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:datacenter_edition:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:datacenter_edition_64-bit:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:enterprise_edition:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:enterprise_edition_64-bit:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:standard:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:standard_64-bit:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:web_edition:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2000:none:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2000:sp1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2000:sp2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2000:sp3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2003:datacenter_sp1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2003:enterprise_sp1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2003:standard_sp1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2003:web_edition_sp1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_xp:*:*:home:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_xp:*:*:media_center:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_xp:*:*:pro:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_xp:*:*:x64:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_xp:*:sp1:home:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_xp:*:sp1:media_center:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_xp:*:sp1:pro:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_xp:*:sp2:media_center:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_xp:*:sp2:pro:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_xp:-:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-14T19:06Z",
    "lastModifiedDate" : "2019-04-30T14:27Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0006",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "windows_media_player",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_2000",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_2003_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "r2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_98",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_98se",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_me",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_xp",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18835",
          "name" : "18835",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/423",
          "name" : "423",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1015627",
          "name" : "1015627",
          "refsource" : "SECTRACK",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.eeye.com/html/research/advisories/AD20060214.html",
          "name" : "http://www.eeye.com/html/research/advisories/AD20060214.html",
          "refsource" : "MISC",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/291396",
          "name" : "VU#291396",
          "refsource" : "CERT-VN",
          "tags" : [ "Third Party Advisory", "US Government Resource" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/424983/100/0/threaded",
          "name" : "20060214 [EEYEB-20051017] Windows Media Player BMP Heap Overflow",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/425158/100/0/threaded",
          "name" : "20060215 Windows Media Player BMP Heap Overflow (MS06-005)",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16633",
          "name" : "16633",
          "refsource" : "BID",
          "tags" : [ "Exploit", "Patch" ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA06-045A.html",
          "name" : "TA06-045A",
          "refsource" : "CERT",
          "tags" : [ "Third Party Advisory", "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0574",
          "name" : "ADV-2006-0574",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-005",
          "name" : "MS06-005",
          "refsource" : "MS",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24488",
          "name" : "win-media-player-bmp-bo(24488)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1256",
          "name" : "oval:org.mitre.oval:def:1256",
          "refsource" : "OVAL",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1578",
          "name" : "oval:org.mitre.oval:def:1578",
          "refsource" : "OVAL",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1598",
          "name" : "oval:org.mitre.oval:def:1598",
          "refsource" : "OVAL",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1661",
          "name" : "oval:org.mitre.oval:def:1661",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Heap-based buffer overflow in the bitmap processing routine in Microsoft Windows Media Player 7.1 on Windows 2000 SP4, Media Player 9 on Windows 2000 SP4 and XP SP1, and Media Player 10 on XP SP1 and SP2 allows remote attackers to execute arbitrary code via a crafted bitmap (.BMP) file that specifies a size of 0 but contains additional data."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:windows_media_player:7.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:windows_media_player:9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:windows_media_player:10:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2000:*:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2000:*:sp4:*:fr:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:r2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_98:*:gold:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_98se:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_me:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_xp:*:sp1:tablet_pc:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_xp:*:sp2:tablet_pc:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-14T22:06Z",
    "lastModifiedDate" : "2018-10-19T15:41Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0007",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "office",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2000",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2003",
                    "version_affected" : "="
                  }, {
                    "version_value" : "xp",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://archives.neohapsis.com/archives/vulnwatch/2006-q3/0005.html",
          "name" : "20060712 NSFOCUS SA2006-04 : Microsoft Office GIF Filter Buffer Overflow Vulnerability",
          "refsource" : "VULNWATCH",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/21013",
          "name" : "21013",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1016470",
          "name" : "1016470",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/668564",
          "name" : "VU#668564",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.osvdb.org/27146",
          "name" : "27146",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/439887/100/0/threaded",
          "name" : "20060712 NSFOCUS SA2006-04 : Microsoft Office GIF Filter Buffer Overflow Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/18915",
          "name" : "18915",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA06-192A.html",
          "name" : "TA06-192A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/2757",
          "name" : "ADV-2006-2757",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-039",
          "name" : "MS06-039",
          "refsource" : "MS",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A21",
          "name" : "oval:org.mitre.oval:def:21",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Buffer overflow in GIFIMP32.FLT, as used in Microsoft Office 2003 SP1 and SP2, Office XP SP3, Office 2000 SP3, and other products, allows user-assisted attackers to execute arbitrary code via a crafted GIF image that triggers memory corruption when it is parsed."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:2000:sp3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:2003:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:2003:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:xp:sp3:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2006-07-11T21:05Z",
    "lastModifiedDate" : "2018-10-19T15:41Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0008",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "office",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2003",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_2003_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "datacenter_64-bit",
                    "version_affected" : "="
                  }, {
                    "version_value" : "enterprise",
                    "version_affected" : "="
                  }, {
                    "version_value" : "enterprise_64-bit",
                    "version_affected" : "="
                  }, {
                    "version_value" : "r2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "standard",
                    "version_affected" : "="
                  }, {
                    "version_value" : "standard_64-bit",
                    "version_affected" : "="
                  }, {
                    "version_value" : "web",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_xp",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-264"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18859",
          "name" : "18859",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1015631",
          "name" : "1015631",
          "refsource" : "SECTRACK",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/739844",
          "name" : "VU#739844",
          "refsource" : "CERT-VN",
          "tags" : [ "Third Party Advisory", "US Government Resource" ]
        }, {
          "url" : "http://www.ryanstyle.com/alert/my/5/ms06_009_eng.html",
          "name" : "http://www.ryanstyle.com/alert/my/5/ms06_009_eng.html",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/425141/100/0/threaded",
          "name" : "20060215 Security advisory: Windows IME Vulnerability (MS06-009)",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16643",
          "name" : "16643",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0578",
          "name" : "ADV-2006-0578",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-009",
          "name" : "MS06-009",
          "refsource" : "MS",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24492",
          "name" : "win-korean-ime-privilege-elevation(24492)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1595",
          "name" : "oval:org.mitre.oval:def:1595",
          "refsource" : "OVAL",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1650",
          "name" : "oval:org.mitre.oval:def:1650",
          "refsource" : "OVAL",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1664",
          "name" : "oval:org.mitre.oval:def:1664",
          "refsource" : "OVAL",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1688",
          "name" : "oval:org.mitre.oval:def:1688",
          "refsource" : "OVAL",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A727",
          "name" : "oval:org.mitre.oval:def:727",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The ShellAbout API call in Korean Input Method Editor (IME) in Korean versions of Microsoft Windows XP SP1 and SP2, Windows Server 2003 up to SP1, and Office 2003, allows local users to gain privileges by launching the \"shell about dialog box\" and clicking the \"End-User License Agreement\" link, which executes Notepad with the privileges of the program that displays the about box."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:2003:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:2003:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:2003:sp2:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:datacenter_64-bit:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:enterprise:*:64-bit:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:enterprise:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:enterprise_64-bit:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:enterprise_64-bit:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:r2:*:64-bit:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:r2:*:datacenter_64-bit:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:r2:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:standard:*:64-bit:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:standard:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:standard_64-bit:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:web:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:web:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_xp:*:*:64-bit:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_xp:*:*:home:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_xp:*:*:media_center:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_xp:*:gold:professional:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_xp:*:sp1:home:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_xp:*:sp1:media_center:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_xp:*:sp2:home:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_xp:*:sp2:media_center:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_xp:*:sp2:tablet_pc:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.2
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 3.9,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-14T19:06Z",
    "lastModifiedDate" : "2018-10-30T16:25Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0009",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "office",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2000",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2003",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2004",
                    "version_affected" : "="
                  }, {
                    "version_value" : "v.x",
                    "version_affected" : "="
                  }, {
                    "version_value" : "xp",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "works",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2000",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2001",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2002",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2003",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2004",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2005",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2006",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://archives.neohapsis.com/archives/fulldisclosure/2006-08/0597.html",
          "name" : "20060822 Major updates in PowerPoint FAQ document - not a 0-day issue",
          "refsource" : "FULLDISC",
          "tags" : [ ]
        }, {
          "url" : "http://blogs.securiteam.com/?author=28",
          "name" : "http://blogs.securiteam.com/?author=28",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://blogs.securiteam.com/?p=557",
          "name" : "http://blogs.securiteam.com/?p=557",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://blogs.securiteam.com/?p=559",
          "name" : "http://blogs.securiteam.com/?p=559",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://isc.sans.org/diary.php?storyid=1618",
          "name" : "http://isc.sans.org/diary.php?storyid=1618",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://lists.grok.org.uk/pipermail/full-disclosure/2006-September/049540.html",
          "name" : "20060919 New PowerPoint 0-day Trojan in the wild",
          "refsource" : "FULLDISC",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/19138",
          "name" : "19138",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/19238",
          "name" : "19238",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1015766",
          "name" : "1015766",
          "refsource" : "SECTRACK",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://securitytracker.com/id?1016720",
          "name" : "1016720",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1016886",
          "name" : "1016886",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://support.avaya.com/elmodocs2/security/ASA-2006-069.htm",
          "name" : "http://support.avaya.com/elmodocs2/security/ASA-2006-069.htm",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.darkreading.com/document.asp?doc_id=101970",
          "name" : "http://www.darkreading.com/document.asp?doc_id=101970",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/682820",
          "name" : "VU#682820",
          "refsource" : "CERT-VN",
          "tags" : [ "Third Party Advisory", "US Government Resource" ]
        }, {
          "url" : "http://www.osvdb.org/23903",
          "name" : "23903",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/427671/100/0/threaded",
          "name" : "20060314 SYMSA-2006-001: Buffer overflow in Microsoft Office 2000, Office XP (2002), and Office 2003 Routing Slip Metadata",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/432004/30/5340/threaded",
          "name" : "20060422 PowerPoint Phishing Trojan",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/443890/100/0/threaded",
          "name" : "20060819 New PowerPoint 0-day and Trojan - FAQ document ready",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/444051/100/200/threaded",
          "name" : "20060822 Major updates in PowerPoint FAQ document - not a 0-day issue",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/446370/100/0/threaded",
          "name" : "20060919 New PowerPoint 0-day Trojan in the wild",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/446425/100/0/threaded",
          "name" : "20060919 Microsoft PowerPoint 0-day Vulnerability FAQ - September written",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/17000",
          "name" : "17000",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/20059",
          "name" : "20059",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.symantec.com/enterprise/research/SYMSA-2006-001.txt",
          "name" : "http://www.symantec.com/enterprise/research/SYMSA-2006-001.txt",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.symantec.com/security_response/writeup.jsp?docid=2006-091810-5028-99",
          "name" : "http://www.symantec.com/security_response/writeup.jsp?docid=2006-091810-5028-99",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=TROJ%5FMDROPPER%2EBH",
          "name" : "http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=TROJ%5FMDROPPER%2EBH",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA06-073A.html",
          "name" : "TA06-073A",
          "refsource" : "CERT",
          "tags" : [ "Third Party Advisory", "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0950",
          "name" : "ADV-2006-0950",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/3678",
          "name" : "ADV-2006-3678",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-012",
          "name" : "MS06-012",
          "refsource" : "MS",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/25009",
          "name" : "office-routing-slip-bo(25009)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/29009",
          "name" : "powerpoint-presentation-code-execution(29009)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1504",
          "name" : "oval:org.mitre.oval:def:1504",
          "refsource" : "OVAL",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1553",
          "name" : "oval:org.mitre.oval:def:1553",
          "refsource" : "OVAL",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1653",
          "name" : "oval:org.mitre.oval:def:1653",
          "refsource" : "OVAL",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A798",
          "name" : "oval:org.mitre.oval:def:798",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Buffer overflow in Microsoft Office 2000 SP3, XP SP3, and other versions and packages, allows user-assisted attackers to execute arbitrary code via a routing slip that is longer than specified by the provided length field, as exploited by malware such as TROJ_MDROPPER.BH and Trojan.PPDropper.E in attacks against PowerPoint."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:2000:sp3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:2003:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:2003:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:2004:*:mac:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:v.x:*:mac:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:xp:sp3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:works:2000:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:works:2001:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:works:2002:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:works:2003:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:works:2004:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:works:2005:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:works:2006:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:H/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "HIGH",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.1
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 4.9,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2006-03-14T23:02Z",
    "lastModifiedDate" : "2018-10-19T15:41Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0010",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "windows_2000",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_2003_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "datacenter_64-bit",
                    "version_affected" : "="
                  }, {
                    "version_value" : "enterprise",
                    "version_affected" : "="
                  }, {
                    "version_value" : "enterprise_64-bit",
                    "version_affected" : "="
                  }, {
                    "version_value" : "r2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "standard",
                    "version_affected" : "="
                  }, {
                    "version_value" : "standard_64-bit",
                    "version_affected" : "="
                  }, {
                    "version_value" : "web",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_98",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_98se",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_me",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_nt",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.5.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_xp",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://seclists.org/fulldisclosure/2006/Jan/363",
          "name" : "20060110 [EEYEB-2000801] - Windows Embedded Open Type (EOT) Font Heap Overflow Vulnerability",
          "refsource" : "FULLDISC",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18311",
          "name" : "18311",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18365",
          "name" : "18365",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18391",
          "name" : "18391",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1015459",
          "name" : "1015459",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://support.avaya.com/elmodocs2/security/ASA-2006-004.htm",
          "name" : "http://support.avaya.com/elmodocs2/security/ASA-2006-004.htm",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.eeye.com/html/Research/Advisories/EEYEB20050801.html",
          "name" : "EEYEB20050801",
          "refsource" : "EEYE",
          "tags" : [ ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/915930",
          "name" : "VU#915930",
          "refsource" : "CERT-VN",
          "tags" : [ "Third Party Advisory", "US Government Resource" ]
        }, {
          "url" : "http://www.osvdb.org/18829",
          "name" : "18829",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/421885/100/0/threaded",
          "name" : "20060110 [EEYEB-2000801] - Windows Embedded Open Type (EOT) Font Heap Overflow Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16194",
          "name" : "16194",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA06-010A.html",
          "name" : "TA06-010A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0118",
          "name" : "ADV-2006-0118",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www130.nortelnetworks.com/cgi-bin/eserv/cs/main.jsp?cscat=BLTNDETAIL&DocumentOID=375525",
          "name" : "http://www130.nortelnetworks.com/cgi-bin/eserv/cs/main.jsp?cscat=BLTNDETAIL&DocumentOID=375525",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-002",
          "name" : "MS06-002",
          "refsource" : "MS",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/23922",
          "name" : "win-embedded-fonts-bo(23922)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1126",
          "name" : "oval:org.mitre.oval:def:1126",
          "refsource" : "OVAL",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1185",
          "name" : "oval:org.mitre.oval:def:1185",
          "refsource" : "OVAL",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1462",
          "name" : "oval:org.mitre.oval:def:1462",
          "refsource" : "OVAL",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1491",
          "name" : "oval:org.mitre.oval:def:1491",
          "refsource" : "OVAL",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A698",
          "name" : "oval:org.mitre.oval:def:698",
          "refsource" : "OVAL",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A714",
          "name" : "oval:org.mitre.oval:def:714",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Heap-based buffer overflow in T2EMBED.DLL in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 up to SP1, Windows 98, and Windows ME allows remote attackers to execute arbitrary code via an e-mail message or web page with a crafted Embedded Open Type (EOT) web font that triggers the overflow during decompression."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2000:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2000:*:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2000:*:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2000:*:sp3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2000:*:sp4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:datacenter_64-bit:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:enterprise:*:64-bit:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:enterprise:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:enterprise_64-bit:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:enterprise_64-bit:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:r2:*:64-bit:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:r2:*:datacenter_64-bit:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:r2:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:standard:*:64-bit:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:standard:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:standard_64-bit:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:web:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:web:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_98:*:gold:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_98se:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_me:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_nt:3.5.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_nt:3.5.1:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_nt:3.5.1:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_nt:3.5.1:sp3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_nt:3.5.1:sp4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_nt:3.5.1:sp5:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_nt:3.5.1:sp5:alpha:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_nt:4.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_nt:4.0:*:alpha:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_nt:4.0:*:enterprise_server:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_nt:4.0:*:server:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_nt:4.0:*:terminal_server:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_nt:4.0:*:terminal_server_alpha:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_nt:4.0:*:workstation:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_nt:4.0:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_nt:4.0:sp1:alpha:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_nt:4.0:sp1:enterprise_server:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_nt:4.0:sp1:server:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_nt:4.0:sp1:terminal_server:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_nt:4.0:sp1:workstation:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_nt:4.0:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_nt:4.0:sp2:alpha:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_nt:4.0:sp2:enterprise_server:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_nt:4.0:sp2:server:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_nt:4.0:sp2:terminal_server:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_nt:4.0:sp2:workstation:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_nt:4.0:sp3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_nt:4.0:sp3:alpha:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_nt:4.0:sp3:enterprise_server:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_nt:4.0:sp3:server:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_nt:4.0:sp3:terminal_server:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_nt:4.0:sp3:workstation:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_nt:4.0:sp4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_nt:4.0:sp4:alpha:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_nt:4.0:sp4:enterprise_server:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_nt:4.0:sp4:server:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_nt:4.0:sp4:terminal_server:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_nt:4.0:sp4:workstation:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_nt:4.0:sp5:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_nt:4.0:sp5:alpha:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_nt:4.0:sp5:enterprise_server:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_nt:4.0:sp5:server:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_nt:4.0:sp5:terminal_server:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_nt:4.0:sp5:workstation:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_nt:4.0:sp6:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_nt:4.0:sp6:alpha:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_nt:4.0:sp6:enterprise_server:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_nt:4.0:sp6:server:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_nt:4.0:sp6:terminal_server:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_nt:4.0:sp6:workstation:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_nt:4.0:sp6a:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_nt:4.0:sp6a:alpha:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_nt:4.0:sp6a:enterprise_server:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_nt:4.0:sp6a:server:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_nt:4.0:sp6a:terminal_server:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_nt:4.0:sp6a:workstation:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_xp:*:*:64-bit:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_xp:*:*:home:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_xp:*:*:media_center:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_xp:*:gold:professional:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_xp:*:sp1:home:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_xp:*:sp1:media_center:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_xp:*:sp2:home:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_xp:*:sp2:media_center:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_xp:*:sp2:tablet_pc:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2006-01-10T22:03Z",
    "lastModifiedDate" : "2019-04-30T14:27Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0011",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ ]
        } ]
      },
      "references" : {
        "reference_data" : [ ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "** REJECT **  DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2006. Notes: none."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ ]
    },
    "impact" : { },
    "publishedDate" : "2017-05-11T14:29Z",
    "lastModifiedDate" : "2017-05-11T14:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0012",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "windows_2000",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_2003_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "datacenter_64-bit",
                    "version_affected" : "="
                  }, {
                    "version_value" : "enterprise",
                    "version_affected" : "="
                  }, {
                    "version_value" : "enterprise_64-bit",
                    "version_affected" : "="
                  }, {
                    "version_value" : "r2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "standard",
                    "version_affected" : "="
                  }, {
                    "version_value" : "standard_64-bit",
                    "version_affected" : "="
                  }, {
                    "version_value" : "web",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_98",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_98se",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_me",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_xp",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/19606",
          "name" : "19606",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1015897",
          "name" : "1015897",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/641460",
          "name" : "VU#641460",
          "refsource" : "CERT-VN",
          "tags" : [ "Third Party Advisory", "US Government Resource" ]
        }, {
          "url" : "http://www.osvdb.org/24516",
          "name" : "24516",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/17464",
          "name" : "17464",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA06-101A.html",
          "name" : "TA06-101A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/1320",
          "name" : "ADV-2006-1320",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-015",
          "name" : "MS06-015",
          "refsource" : "MS",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/25554",
          "name" : "win-explorer-com-code-execution(25554)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1191",
          "name" : "oval:org.mitre.oval:def:1191",
          "refsource" : "OVAL",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1448",
          "name" : "oval:org.mitre.oval:def:1448",
          "refsource" : "OVAL",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1679",
          "name" : "oval:org.mitre.oval:def:1679",
          "refsource" : "OVAL",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1743",
          "name" : "oval:org.mitre.oval:def:1743",
          "refsource" : "OVAL",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1764",
          "name" : "oval:org.mitre.oval:def:1764",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in Windows Explorer in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 allows remote attackers to execute arbitrary code via attack vectors involving COM objects and \"crafted files and directories,\" aka the \"Windows Shell Vulnerability.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2000:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2000:*:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2000:*:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2000:*:sp3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2000:*:sp4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:datacenter_64-bit:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:enterprise:*:64-bit:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:enterprise:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:enterprise_64-bit:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:enterprise_64-bit:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:r2:*:64-bit:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:r2:*:datacenter_64-bit:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:r2:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:standard:*:64-bit:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:standard:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:standard_64-bit:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:web:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:web:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_98:*:gold:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_98se:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_me:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_xp:*:*:64-bit:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_xp:*:*:home:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_xp:*:*:media_center:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_xp:*:gold:professional:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_xp:*:sp1:home:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_xp:*:sp1:media_center:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_xp:*:sp2:home:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_xp:*:sp2:media_center:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_xp:*:sp2:tablet_pc:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:H/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "HIGH",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.1
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 4.9,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2006-04-12T00:02Z",
    "lastModifiedDate" : "2019-04-30T14:27Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0013",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "windows_2003_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "datacenter_64-bit",
                    "version_affected" : "="
                  }, {
                    "version_value" : "enterprise",
                    "version_affected" : "="
                  }, {
                    "version_value" : "enterprise_64-bit",
                    "version_affected" : "="
                  }, {
                    "version_value" : "r2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "standard",
                    "version_affected" : "="
                  }, {
                    "version_value" : "standard_64-bit",
                    "version_affected" : "="
                  }, {
                    "version_value" : "web",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_xp",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18857",
          "name" : "18857",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1015630",
          "name" : "1015630",
          "refsource" : "SECTRACK",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/388900",
          "name" : "VU#388900",
          "refsource" : "CERT-VN",
          "tags" : [ "Third Party Advisory", "US Government Resource" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16636",
          "name" : "16636",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0577",
          "name" : "ADV-2006-0577",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-008",
          "name" : "MS06-008",
          "refsource" : "MS",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24491",
          "name" : "msrpc-webclient-message-bo(24491)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1220",
          "name" : "oval:org.mitre.oval:def:1220",
          "refsource" : "OVAL",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1547",
          "name" : "oval:org.mitre.oval:def:1547",
          "refsource" : "OVAL",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1602",
          "name" : "oval:org.mitre.oval:def:1602",
          "refsource" : "OVAL",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A683",
          "name" : "oval:org.mitre.oval:def:683",
          "refsource" : "OVAL",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A716",
          "name" : "oval:org.mitre.oval:def:716",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Buffer overflow in the Web Client service (WebClnt.dll) for Microsoft Windows XP SP1 and SP2, and Server 2003 up to SP1, allows remote authenticated users or Guests to execute arbitrary code via crafted RPC requests, a different vulnerability than CVE-2005-1207."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:datacenter_64-bit:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:enterprise:*:64-bit:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:enterprise:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:enterprise_64-bit:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:enterprise_64-bit:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:r2:*:64-bit:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:r2:*:datacenter_64-bit:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:r2:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:standard:*:64-bit:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:standard:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:standard_64-bit:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:web:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:web:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_xp:*:*:64-bit:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_xp:*:*:home:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_xp:*:gold:professional:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_xp:*:sp1:home:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_xp:*:sp2:home:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.5
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-14T19:06Z",
    "lastModifiedDate" : "2018-10-12T21:38Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0014",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "outlook_express",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.grok.org.uk/pipermail/full-disclosure/2006-April/045003.html",
          "name" : "20060411 ZDI-06-007: Microsoft Windows Address Book (WAB) File Format Parsing Vulnerability",
          "refsource" : "FULLDISC",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/19617",
          "name" : "19617",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/691",
          "name" : "691",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1015898",
          "name" : "1015898",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/430645/100/0/threaded",
          "name" : "20060411 ZDI-06-007: Microsoft Windows Address Book (WAB) File Format Parsing Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/17459",
          "name" : "17459",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/1321",
          "name" : "ADV-2006-1321",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.zerodayinitiative.com/advisories/ZDI-06-007.html",
          "name" : "http://www.zerodayinitiative.com/advisories/ZDI-06-007.html",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-016",
          "name" : "MS06-016",
          "refsource" : "MS",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/25535",
          "name" : "outlook-express-wab-bo(25535)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1611",
          "name" : "oval:org.mitre.oval:def:1611",
          "refsource" : "OVAL",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1682",
          "name" : "oval:org.mitre.oval:def:1682",
          "refsource" : "OVAL",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1769",
          "name" : "oval:org.mitre.oval:def:1769",
          "refsource" : "OVAL",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1771",
          "name" : "oval:org.mitre.oval:def:1771",
          "refsource" : "OVAL",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1780",
          "name" : "oval:org.mitre.oval:def:1780",
          "refsource" : "OVAL",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1791",
          "name" : "oval:org.mitre.oval:def:1791",
          "refsource" : "OVAL",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A812",
          "name" : "oval:org.mitre.oval:def:812",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Buffer overflow in Microsoft Outlook Express 5.5 and 6 allows remote attackers to execute arbitrary code via a crafted Windows Address Book (WAB) file containing \"certain Unicode strings\" and modified length values."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:outlook_express:5.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:outlook_express:5.5:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:outlook_express:5.5:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:outlook_express:6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:outlook_express:6.0:sp1:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:H/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "HIGH",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.1
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 4.9,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2006-04-12T00:02Z",
    "lastModifiedDate" : "2018-10-19T15:41Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0015",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "frontpage_server_extensions",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2002",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "sharepoint_team_services",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/19623",
          "name" : "19623",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/704",
          "name" : "704",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1015895",
          "name" : "1015895",
          "refsource" : "SECTRACK",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://securitytracker.com/id?1015896",
          "name" : "1015896",
          "refsource" : "SECTRACK",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.argeniss.com/research/ARGENISS-ADV-040602.txt",
          "name" : "http://www.argeniss.com/research/ARGENISS-ADV-040602.txt",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/430803/100/0/threaded",
          "name" : "20060412 Vulnerability in Microsoft FrontPage Server Extensions Could Allow Cross-Site Scripting",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/17452",
          "name" : "17452",
          "refsource" : "BID",
          "tags" : [ "Exploit", "Patch" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/1322",
          "name" : "ADV-2006-1322",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-017",
          "name" : "MS06-017",
          "refsource" : "MS",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/25537",
          "name" : "fpse-html-xss(25537)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1748",
          "name" : "oval:org.mitre.oval:def:1748",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in _vti_bin/_vti_adm/fpadmdll.dll in Microsoft FrontPage Server Extensions 2002 and SharePoint Team Services allows remote attackers to inject arbitrary web script or HTML, then leverage the attack to execute arbitrary programs or create new accounts, via the (1) operation, (2) command, and (3) name parameters."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:frontpage_server_extensions:2002:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:sharepoint_team_services:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-04-11T23:02Z",
    "lastModifiedDate" : "2018-10-19T15:42Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0018",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ ]
        } ]
      },
      "references" : {
        "reference_data" : [ ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2005-3899.  Reason: This candidate is a duplicate of CVE-2005-3899.  Notes: All CVE users should reference CVE-2005-3899 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ ]
    },
    "impact" : { },
    "publishedDate" : "2005-11-29T21:03Z",
    "lastModifiedDate" : "2008-09-10T19:55Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0019",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "kde",
            "product" : {
              "product_data" : [ {
                "product_name" : "kde",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.2.0_beta1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.2.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.2.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.2.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.2.x",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.3.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.3.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.3.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.3.x",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.4.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.4.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.4.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.5.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "ftp://ftp.kde.org/pub/kde/security_patches/post-3.4.3-kdelibs-kjs.diff",
          "name" : "ftp://ftp.kde.org/pub/kde/security_patches/post-3.4.3-kdelibs-kjs.diff",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://secunia.com/advisories/18500",
          "name" : "18500",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18540",
          "name" : "18540",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18552",
          "name" : "18552",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18559",
          "name" : "18559",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18561",
          "name" : "18561",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18570",
          "name" : "18570",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18583",
          "name" : "18583",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18899",
          "name" : "18899",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/364",
          "name" : "364",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1015512",
          "name" : "1015512",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://slackware.com/security/viewer.php?l=slackware-security&y=2006&m=slackware-security.361107",
          "name" : "SSA:2006-045-05",
          "refsource" : "SLACKWARE",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2006/dsa-948",
          "name" : "DSA-948",
          "refsource" : "DEBIAN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.gentoo.org/security/en/glsa/glsa-200601-11.xml",
          "name" : "GLSA-200601-11",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://www.kde.org/info/security/advisory-20060119-1.txt",
          "name" : "http://www.kde.org/info/security/advisory-20060119-1.txt",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDKSA-2006:019",
          "name" : "MDKSA-2006:019",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/22659",
          "name" : "22659",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2006-0184.html",
          "name" : "RHSA-2006:0184",
          "refsource" : "REDHAT",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/422464/100/0/threaded",
          "name" : "20060119 [KDE Security Advisory] kjs encodeuri/decodeuri heap overflow",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/422489/100/0/threaded",
          "name" : "SUSE-SA:2006:003",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/427976/100/0/threaded",
          "name" : "FLSA:178606",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16325",
          "name" : "16325",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/usn-245-1",
          "name" : "USN-245-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0265",
          "name" : "ADV-2006-0265",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24242",
          "name" : "kde-kjs-bo(24242)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11858",
          "name" : "oval:org.mitre.oval:def:11858",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Heap-based buffer overflow in the encodeURI and decodeURI functions in the kjs JavaScript interpreter engine in KDE 3.2.0 through 3.5.0 allows remote attackers to execute arbitrary code via a crafted, UTF-8 encoded URI."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:kde:kde:3.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:kde:kde:3.2.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:kde:kde:3.2.0_beta1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:kde:kde:3.2.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:kde:kde:3.2.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:kde:kde:3.2.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:kde:kde:3.2.x:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:kde:kde:3.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:kde:kde:3.3.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:kde:kde:3.3.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:kde:kde:3.3.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:kde:kde:3.3.x:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:kde:kde:3.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:kde:kde:3.4.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:kde:kde:3.4.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:kde:kde:3.4.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:kde:kde:3.5.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-20T21:03Z",
    "lastModifiedDate" : "2018-10-19T15:42Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0020",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "windows_2000",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_2003_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "r2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "sp1",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_98",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_98se",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_me",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_xp",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-189"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://linuxbox.org/pipermail/funsec/2006-January/002828.html",
          "name" : "[funsec] 20060110 Another WMF flaw without a Microsoft patch",
          "refsource" : "MLIST",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18729",
          "name" : "18729",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18912",
          "name" : "18912",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/312956",
          "name" : "VU#312956",
          "refsource" : "CERT-VN",
          "tags" : [ "Patch", "Third Party Advisory", "US Government Resource" ]
        }, {
          "url" : "http://www.microsoft.com/technet/security/advisory/913333.mspx",
          "name" : "http://www.microsoft.com/technet/security/advisory/913333.mspx",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/22976",
          "name" : "22976",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16516",
          "name" : "16516",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA06-045A.html",
          "name" : "TA06-045A",
          "refsource" : "CERT",
          "tags" : [ "Third Party Advisory", "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0469",
          "name" : "ADV-2006-0469",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-004",
          "name" : "MS06-004",
          "refsource" : "MS",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1638",
          "name" : "oval:org.mitre.oval:def:1638",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "An unspecified Microsoft WMF parsing application, as used in Internet Explorer 5.01 SP4 on Windows 2000 SP4, and 5.5 SP2 on Windows Millennium, and possibly other versions, allows attackers to cause a denial of service (crash) and possibly execute code via a crafted WMF file with a manipulated WMF header size, possibly involving an integer overflow, a different vulnerability than CVE-2005-4560, and aka \"WMF Image Parsing Memory Corruption Vulnerability.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2000:*:sp4:*:fr:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:r2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:sp1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_98:*:gold:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_98se:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_me:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_xp:*:sp1:tablet_pc:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_xp:*:sp2:tablet_pc:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-10T21:03Z",
    "lastModifiedDate" : "2018-10-12T21:38Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0021",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "windows_2003_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "datacenter_64-bit",
                    "version_affected" : "="
                  }, {
                    "version_value" : "enterprise",
                    "version_affected" : "="
                  }, {
                    "version_value" : "enterprise_64-bit",
                    "version_affected" : "="
                  }, {
                    "version_value" : "r2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "standard",
                    "version_affected" : "="
                  }, {
                    "version_value" : "standard_64-bit",
                    "version_affected" : "="
                  }, {
                    "version_value" : "web",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_xp",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18853",
          "name" : "18853",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1015629",
          "name" : "1015629",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/839284",
          "name" : "VU#839284",
          "refsource" : "CERT-VN",
          "tags" : [ "Third Party Advisory", "US Government Resource" ]
        }, {
          "url" : "http://www.securiteam.com/exploits/5PP0T0KI0O.html",
          "name" : "http://www.securiteam.com/exploits/5PP0T0KI0O.html",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/482658/30/4350/threaded",
          "name" : "20071023 SYMSA-2007-012: Microsoft Windows CE IGMP Denial of Service",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16645",
          "name" : "16645",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA06-045A.html",
          "name" : "TA06-045A",
          "refsource" : "CERT",
          "tags" : [ "Third Party Advisory", "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0576",
          "name" : "ADV-2006-0576",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-007",
          "name" : "MS06-007",
          "refsource" : "MS",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24489",
          "name" : "win-igmpv3-dos(24489)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1310",
          "name" : "oval:org.mitre.oval:def:1310",
          "refsource" : "OVAL",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1425",
          "name" : "oval:org.mitre.oval:def:1425",
          "refsource" : "OVAL",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1647",
          "name" : "oval:org.mitre.oval:def:1647",
          "refsource" : "OVAL",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1662",
          "name" : "oval:org.mitre.oval:def:1662",
          "refsource" : "OVAL",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A678",
          "name" : "oval:org.mitre.oval:def:678",
          "refsource" : "OVAL",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/1599",
          "name" : "1599",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Microsoft Windows XP SP1 and SP2, and Server 2003 up to SP1, allows remote attackers to cause a denial of service (hang) via an IGMP packet with an invalid IP option, aka the \"IGMP v3 DoS Vulnerability.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:datacenter_64-bit:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:enterprise:*:64-bit:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:enterprise:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:enterprise_64-bit:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:r2:*:64-bit:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:r2:*:datacenter_64-bit:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:r2:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:standard:*:64-bit:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:standard:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:standard_64-bit:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:web:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:web:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_xp:*:*:64-bit:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_xp:*:*:embedded:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_xp:*:*:home:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_xp:*:*:media_center:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_xp:*:gold:professional:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_xp:*:sp1:64-bit:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_xp:*:sp1:embedded:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_xp:*:sp1:home:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_xp:*:sp1:media_center:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_xp:*:sp2:home:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_xp:*:sp2:media_center:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_xp:*:sp2:tablet_pc:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.8
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-14T19:06Z",
    "lastModifiedDate" : "2018-10-19T15:42Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0022",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "powerpoint",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2000",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2002",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2003",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2004",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/20633",
          "name" : "20633",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1016287",
          "name" : "1016287",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/190089",
          "name" : "VU#190089",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.osvdb.org/26435",
          "name" : "26435",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/18382",
          "name" : "18382",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA06-164A.html",
          "name" : "TA06-164A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/2325",
          "name" : "ADV-2006-2325",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-028",
          "name" : "MS06-028",
          "refsource" : "MS",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/26784",
          "name" : "powerpoint-record-bo(26784)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1069",
          "name" : "oval:org.mitre.oval:def:1069",
          "refsource" : "OVAL",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1836",
          "name" : "oval:org.mitre.oval:def:1836",
          "refsource" : "OVAL",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1984",
          "name" : "oval:org.mitre.oval:def:1984",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in Microsoft PowerPoint in Microsoft Office 2000 SP3, Office XP SP3, Office 2003 SP1 and SP2, Office 2004 for Mac, and v. X for Mac allows user-assisted attackers to execute arbitrary code via a PowerPoint document with a malformed record, which triggers memory corruption."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:powerpoint:2000:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:powerpoint:2000:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:powerpoint:2000:sp3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:powerpoint:2000:sr1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:powerpoint:2002:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:powerpoint:2002:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:powerpoint:2002:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:powerpoint:2002:sp3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:powerpoint:2003:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:powerpoint:2003:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:powerpoint:2003:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:powerpoint:2003:sp3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:powerpoint:2004:*:mac:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:H/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "HIGH",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.6
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 4.9,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2006-06-13T19:06Z",
    "lastModifiedDate" : "2018-10-12T21:38Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0023",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "windows_xp",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-264"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18756",
          "name" : "18756",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/19238",
          "name" : "19238",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/19313",
          "name" : "19313",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1015595",
          "name" : "1015595",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1015765",
          "name" : "1015765",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://support.avaya.com/elmodocs2/security/ASA-2006-069.htm",
          "name" : "http://support.avaya.com/elmodocs2/security/ASA-2006-069.htm",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.cs.princeton.edu/~sudhakar/papers/winval.pdf",
          "name" : "http://www.cs.princeton.edu/~sudhakar/papers/winval.pdf",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/953860",
          "name" : "VU#953860",
          "refsource" : "CERT-VN",
          "tags" : [ "Third Party Advisory", "US Government Resource" ]
        }, {
          "url" : "http://www.microsoft.com/technet/security/advisory/914457.mspx",
          "name" : "http://www.microsoft.com/technet/security/advisory/914457.mspx",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/423587/100/0/threaded",
          "name" : "20060131 Windows Access Control Demystified",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0417",
          "name" : "ADV-2006-0417",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www130.nortelnetworks.com/cgi-bin/eserv/cs/main.jsp?cscat=BLTNDETAIL&DocumentOID=391523&RenditionID=",
          "name" : "http://www130.nortelnetworks.com/cgi-bin/eserv/cs/main.jsp?cscat=BLTNDETAIL&DocumentOID=391523&RenditionID=",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-011",
          "name" : "MS06-011",
          "refsource" : "MS",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24463",
          "name" : "win-auth-users-insecure-permissions(24463)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1671",
          "name" : "oval:org.mitre.oval:def:1671",
          "refsource" : "OVAL",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1696",
          "name" : "oval:org.mitre.oval:def:1696",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Microsoft Windows XP SP1 and SP2 before August 2004, and possibly other operating systems and versions, uses insecure default ACLs that allow the Authenticated Users group to gain privileges by modifying critical configuration information for the (1) Simple Service Discovery Protocol (SSDP), (2) Universal Plug and Play Device Host (UPnP), (3) NetBT, (4) SCardSvr, (5) DHCP, and (6) DnsCache services, aka \"Permissive Windows Services DACLs.\"  NOTE: the NetBT, SCardSvr, DHCP, DnsCache already require privileged access to exploit."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_xp:*:sp1:tablet_pc:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_xp:*:sp2:tablet_pc:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:S/C:P/I:P/A:P",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 3.1,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-08T02:18Z",
    "lastModifiedDate" : "2018-10-19T15:42Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0024",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "macromedia",
            "product" : {
              "product_data" : [ {
                "product_name" : "flash_player",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.0_r12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0_r50",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.29.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.40.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.47.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.65.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.79.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.19.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.60.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.61.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0_r19",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.22.0",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://docs.info.apple.com/article.html?artnum=307179",
          "name" : "http://docs.info.apple.com/article.html?artnum=307179",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://lists.apple.com/archives/security-announce/2006/May/msg00003.html",
          "name" : "APPLE-SA-2006-05-11",
          "refsource" : "APPLE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.apple.com/archives/security-announce/2007/Dec/msg00002.html",
          "name" : "APPLE-SA-2007-12-17",
          "refsource" : "APPLE",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/19198",
          "name" : "19198",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/19218",
          "name" : "19218",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/19259",
          "name" : "19259",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/19328",
          "name" : "19328",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/20045",
          "name" : "20045",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/20077",
          "name" : "20077",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/28136",
          "name" : "28136",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1015770",
          "name" : "1015770",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.gentoo.org/security/en/glsa/glsa-200603-20.xml",
          "name" : "GLSA-200603-20",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/945060",
          "name" : "VU#945060",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.macromedia.com/devnet/security/security_zone/apsb06-03.html",
          "name" : "http://www.macromedia.com/devnet/security/security_zone/apsb06-03.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.novell.com/linux/security/advisories/2006_15_flashplayer.html",
          "name" : "SUSE-SA:2006:015",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://www.opera.com/docs/changelogs/windows/854/",
          "name" : "http://www.opera.com/docs/changelogs/windows/854/",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/23908",
          "name" : "23908",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2006-0268.html",
          "name" : "RHSA-2006:0268",
          "refsource" : "REDHAT",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/17106",
          "name" : "17106",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/17951",
          "name" : "17951",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA06-075A.html",
          "name" : "TA06-075A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA06-129A.html",
          "name" : "TA06-129A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA06-132A.html",
          "name" : "TA06-132A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA07-352A.html",
          "name" : "TA07-352A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0952",
          "name" : "ADV-2006-0952",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/1262",
          "name" : "ADV-2006-1262",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/1744",
          "name" : "ADV-2006-1744",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/1779",
          "name" : "ADV-2006-1779",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/4238",
          "name" : "ADV-2007-4238",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-020",
          "name" : "MS06-020",
          "refsource" : "MS",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/25005",
          "name" : "macromedia-swf-code-execution(25005)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1894",
          "name" : "oval:org.mitre.oval:def:1894",
          "refsource" : "OVAL",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1922",
          "name" : "oval:org.mitre.oval:def:1922",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple unspecified vulnerabilities in Adobe Flash Player 8.0.22.0 and earlier allow remote attackers to execute arbitrary code via a crafted SWF file."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:macromedia:flash_player:4.0_r12:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:macromedia:flash_player:5.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:macromedia:flash_player:5.0_r50:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:macromedia:flash_player:6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:macromedia:flash_player:6.0.29.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:macromedia:flash_player:6.0.40.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:macromedia:flash_player:6.0.47.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:macromedia:flash_player:6.0.65.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:macromedia:flash_player:6.0.79.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:macromedia:flash_player:7.0.19.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:macromedia:flash_player:7.0.60.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:macromedia:flash_player:7.0.61.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:macromedia:flash_player:7.0_r19:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:macromedia:flash_player:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "8.0.22.0"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:H/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "HIGH",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.1
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 4.9,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2006-03-15T16:06Z",
    "lastModifiedDate" : "2018-10-12T21:38Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0025",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "windows_media_player",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/20626",
          "name" : "20626",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1016284",
          "name" : "1016284",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.idefense.com/intelligence/vulnerabilities/display.php?id=406",
          "name" : "20060613 Windows Media Player PNG Chunk Decoding Stack-Based Buffer Overflow",
          "refsource" : "IDEFENSE",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/608020",
          "name" : "VU#608020",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.osvdb.org/26430",
          "name" : "26430",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/18385",
          "name" : "18385",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA06-164A.html",
          "name" : "TA06-164A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/2322",
          "name" : "ADV-2006-2322",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-024",
          "name" : "MS06-024",
          "refsource" : "MS",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/26788",
          "name" : "win-media-player-png-bo(26788)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1230",
          "name" : "oval:org.mitre.oval:def:1230",
          "refsource" : "OVAL",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1729",
          "name" : "oval:org.mitre.oval:def:1729",
          "refsource" : "OVAL",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1805",
          "name" : "oval:org.mitre.oval:def:1805",
          "refsource" : "OVAL",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1807",
          "name" : "oval:org.mitre.oval:def:1807",
          "refsource" : "OVAL",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1820",
          "name" : "oval:org.mitre.oval:def:1820",
          "refsource" : "OVAL",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1974",
          "name" : "oval:org.mitre.oval:def:1974",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Stack-based buffer overflow in Microsoft Windows Media Player 9 and 10 allows remote attackers to execute arbitrary code via a PNG image with a large chunk size."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:windows_media_player:9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:windows_media_player:10:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2006-06-13T19:06Z",
    "lastModifiedDate" : "2018-10-12T21:38Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0026",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "internet_information_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "internet_information_services",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://archives.neohapsis.com/archives/bugtraq/2006-07/0316.html",
          "name" : "20060718 ASP.DLL Include File Buffer Overflow",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/21006",
          "name" : "21006",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1016466",
          "name" : "1016466",
          "refsource" : "SECTRACK",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/395588",
          "name" : "VU#395588",
          "refsource" : "CERT-VN",
          "tags" : [ "Patch", "US Government Resource" ]
        }, {
          "url" : "http://www.osvdb.org/27152",
          "name" : "27152",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/18858",
          "name" : "18858",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA06-192A.html",
          "name" : "TA06-192A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/2752",
          "name" : "ADV-2006-2752",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-034",
          "name" : "MS06-034",
          "refsource" : "MS",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/26796",
          "name" : "iis-asp-bo(26796)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A435",
          "name" : "oval:org.mitre.oval:def:435",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Buffer overflow in Microsoft Internet Information Services (IIS) 5.0, 5.1, and 6.0 allows local and possibly remote attackers to execute arbitrary code via crafted Active Server Pages (ASP)."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:internet_information_server:5.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:internet_information_server:6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:internet_information_services:5.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.5
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-07-11T22:05Z",
    "lastModifiedDate" : "2018-10-30T16:25Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0027",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "exchange_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2000",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2003",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/20029",
          "name" : "20029",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1016048",
          "name" : "1016048",
          "refsource" : "SECTRACK",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/303452",
          "name" : "VU#303452",
          "refsource" : "CERT-VN",
          "tags" : [ "Patch", "Third Party Advisory", "US Government Resource" ]
        }, {
          "url" : "http://www.osvdb.org/25338",
          "name" : "25338",
          "refsource" : "OSVDB",
          "tags" : [ "Broken Link" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/17908",
          "name" : "17908",
          "refsource" : "BID",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA06-129A.html",
          "name" : "TA06-129A",
          "refsource" : "CERT",
          "tags" : [ "Patch", "Third Party Advisory", "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/1743",
          "name" : "ADV-2006-1743",
          "refsource" : "VUPEN",
          "tags" : [ "Permissions Required" ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-019",
          "name" : "MS06-019",
          "refsource" : "MS",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/25556",
          "name" : "exchange-calendar-code-execution(25556)",
          "refsource" : "XF",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1818",
          "name" : "oval:org.mitre.oval:def:1818",
          "refsource" : "OVAL",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1996",
          "name" : "oval:org.mitre.oval:def:1996",
          "refsource" : "OVAL",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2035",
          "name" : "oval:org.mitre.oval:def:2035",
          "refsource" : "OVAL",
          "tags" : [ "Third Party Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in Microsoft Exchange allows remote attackers to execute arbitrary code via e-mail messages with crafted (1) vCal or (2) iCal Calendar properties."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:exchange_server:2000:sp3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:exchange_server:2003:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:exchange_server:2003:sp2:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-05-10T02:10Z",
    "lastModifiedDate" : "2020-04-09T13:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0028",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "excel",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2000",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2002",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2003",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2004",
                    "version_affected" : "="
                  }, {
                    "version_value" : "x",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "office",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2000",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2003",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2004",
                    "version_affected" : "="
                  }, {
                    "version_value" : "v.x",
                    "version_affected" : "="
                  }, {
                    "version_value" : "xp",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/19138",
          "name" : "19138",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/19238",
          "name" : "19238",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/583",
          "name" : "583",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1015766",
          "name" : "1015766",
          "refsource" : "SECTRACK",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://support.avaya.com/elmodocs2/security/ASA-2006-069.htm",
          "name" : "http://support.avaya.com/elmodocs2/security/ASA-2006-069.htm",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/339878",
          "name" : "VU#339878",
          "refsource" : "CERT-VN",
          "tags" : [ "Third Party Advisory", "US Government Resource" ]
        }, {
          "url" : "http://www.osvdb.org/23899",
          "name" : "23899",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/427632/100/0/threaded",
          "name" : "20060314 ZDI-06-004: Microsoft Excel File Format Parsing Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA06-073A.html",
          "name" : "TA06-073A",
          "refsource" : "CERT",
          "tags" : [ "Third Party Advisory", "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0950",
          "name" : "ADV-2006-0950",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.zerodayinitiative.com/advisories/ZDI-06-004.html",
          "name" : "http://www.zerodayinitiative.com/advisories/ZDI-06-004.html",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-012",
          "name" : "MS06-012",
          "refsource" : "MS",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/25225",
          "name" : "excel-parsing-format-file-bo(25225)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1158",
          "name" : "oval:org.mitre.oval:def:1158",
          "refsource" : "OVAL",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1411",
          "name" : "oval:org.mitre.oval:def:1411",
          "refsource" : "OVAL",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1509",
          "name" : "oval:org.mitre.oval:def:1509",
          "refsource" : "OVAL",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1635",
          "name" : "oval:org.mitre.oval:def:1635",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in Microsoft Excel 2000, 2002, and 2003, in Microsoft Office 2000 SP3 and other packages, allows user-assisted attackers to execute arbitrary code via a BIFF parsing format file containing malformed BOOLERR records that lead to memory corruption, probably involving invalid pointers."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:excel:2000:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:excel:2002:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:excel:2003:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:excel:2004:*:mac_os_x:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:excel:x:*:mac_os_x:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:2000:sp3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:2003:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:2003:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:2004:*:mac:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:v.x:*:mac:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:xp:sp3:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:H/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "HIGH",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.1
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 4.9,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2006-03-14T23:02Z",
    "lastModifiedDate" : "2018-10-19T15:42Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0029",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "excel",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2000",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2002",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2003",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2004",
                    "version_affected" : "="
                  }, {
                    "version_value" : "x",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "office",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2000",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2003",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2004",
                    "version_affected" : "="
                  }, {
                    "version_value" : "v.x",
                    "version_affected" : "="
                  }, {
                    "version_value" : "xp",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/19138",
          "name" : "19138",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/19238",
          "name" : "19238",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/585",
          "name" : "585",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/586",
          "name" : "586",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1015766",
          "name" : "1015766",
          "refsource" : "SECTRACK",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://support.avaya.com/elmodocs2/security/ASA-2006-069.htm",
          "name" : "http://support.avaya.com/elmodocs2/security/ASA-2006-069.htm",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/235774",
          "name" : "VU#235774",
          "refsource" : "CERT-VN",
          "tags" : [ "Third Party Advisory", "US Government Resource" ]
        }, {
          "url" : "http://www.osvdb.org/23900",
          "name" : "23900",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA06-073A.html",
          "name" : "TA06-073A",
          "refsource" : "CERT",
          "tags" : [ "Third Party Advisory", "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0950",
          "name" : "ADV-2006-0950",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-012",
          "name" : "MS06-012",
          "refsource" : "MS",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/25227",
          "name" : "excel-description-bo(25227)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1522",
          "name" : "oval:org.mitre.oval:def:1522",
          "refsource" : "OVAL",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1570",
          "name" : "oval:org.mitre.oval:def:1570",
          "refsource" : "OVAL",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1579",
          "name" : "oval:org.mitre.oval:def:1579",
          "refsource" : "OVAL",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1633",
          "name" : "oval:org.mitre.oval:def:1633",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in Microsoft Excel 2000, 2002, and 2003, in Microsoft Office 2000 SP3 and other packages, allows user-assisted attackers to execute arbitrary code via an Excel file with a malformed description, which leads to memory corruption."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:excel:2000:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:excel:2002:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:excel:2003:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:excel:2004:*:mac_os_x:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:excel:x:*:mac_os_x:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:2000:sp3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:2003:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:2003:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:2004:*:mac:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:v.x:*:mac:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:xp:sp3:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:H/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "HIGH",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.1
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 4.9,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2006-03-14T23:02Z",
    "lastModifiedDate" : "2018-10-12T21:38Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0030",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "excel",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2000",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2002",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2003",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2004",
                    "version_affected" : "="
                  }, {
                    "version_value" : "x",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "office",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2000",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2003",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2004",
                    "version_affected" : "="
                  }, {
                    "version_value" : "v.x",
                    "version_affected" : "="
                  }, {
                    "version_value" : "xp",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/19138",
          "name" : "19138",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/19238",
          "name" : "19238",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1015766",
          "name" : "1015766",
          "refsource" : "SECTRACK",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://support.avaya.com/elmodocs2/security/ASA-2006-069.htm",
          "name" : "http://support.avaya.com/elmodocs2/security/ASA-2006-069.htm",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/123222",
          "name" : "VU#123222",
          "refsource" : "CERT-VN",
          "tags" : [ "Third Party Advisory", "US Government Resource" ]
        }, {
          "url" : "http://www.osvdb.org/23901",
          "name" : "23901",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16181",
          "name" : "16181",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA06-073A.html",
          "name" : "TA06-073A",
          "refsource" : "CERT",
          "tags" : [ "Third Party Advisory", "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0950",
          "name" : "ADV-2006-0950",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-012",
          "name" : "MS06-012",
          "refsource" : "MS",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/25229",
          "name" : "excel-graphic-bo(25229)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1401",
          "name" : "oval:org.mitre.oval:def:1401",
          "refsource" : "OVAL",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1510",
          "name" : "oval:org.mitre.oval:def:1510",
          "refsource" : "OVAL",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1630",
          "name" : "oval:org.mitre.oval:def:1630",
          "refsource" : "OVAL",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1666",
          "name" : "oval:org.mitre.oval:def:1666",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in Microsoft Excel 2000, 2002, and 2003, in Microsoft Office 2000 SP3 and other packages, allows user-assisted attackers to execute arbitrary code via an Excel file with a malformed graphic, which leads to memory corruption."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:excel:2000:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:excel:2002:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:excel:2003:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:excel:2004:*:mac_os_x:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:excel:x:*:mac_os_x:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:2000:sp3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:2003:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:2003:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:2004:*:mac:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:v.x:*:mac:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:xp:sp3:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:H/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "HIGH",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.1
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 4.9,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2006-03-14T23:02Z",
    "lastModifiedDate" : "2018-10-12T21:38Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0031",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "office",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2000",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2003",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2004",
                    "version_affected" : "="
                  }, {
                    "version_value" : "v.x",
                    "version_affected" : "="
                  }, {
                    "version_value" : "xp",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://archives.neohapsis.com/archives/fulldisclosure/2006-02/1521.html",
          "name" : "20060314 [xfocus-SD-060314]Microsoft Office Excel Buffer Overflow Vulnerability",
          "refsource" : "FULLDISC",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/19138",
          "name" : "19138",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/19238",
          "name" : "19238",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/589",
          "name" : "589",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1015766",
          "name" : "1015766",
          "refsource" : "SECTRACK",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://support.avaya.com/elmodocs2/security/ASA-2006-069.htm",
          "name" : "http://support.avaya.com/elmodocs2/security/ASA-2006-069.htm",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/104302",
          "name" : "VU#104302",
          "refsource" : "CERT-VN",
          "tags" : [ "Third Party Advisory", "US Government Resource" ]
        }, {
          "url" : "http://www.osvdb.org/23902",
          "name" : "23902",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/427699/100/0/threaded",
          "name" : "20060315 [xfocus-SD-060314]Microsoft Office Excel Buffer Overflow Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/17101",
          "name" : "17101",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA06-073A.html",
          "name" : "TA06-073A",
          "refsource" : "CERT",
          "tags" : [ "Third Party Advisory", "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0950",
          "name" : "ADV-2006-0950",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-012",
          "name" : "MS06-012",
          "refsource" : "MS",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/25228",
          "name" : "excel-record-bo(25228)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1327",
          "name" : "oval:org.mitre.oval:def:1327",
          "refsource" : "OVAL",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1525",
          "name" : "oval:org.mitre.oval:def:1525",
          "refsource" : "OVAL",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1750",
          "name" : "oval:org.mitre.oval:def:1750",
          "refsource" : "OVAL",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A763",
          "name" : "oval:org.mitre.oval:def:763",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Stack-based buffer overflow in Microsoft Excel 2000, 2002, and 2003, in Microsoft Office 2000 SP3 and other packages, allows user-assisted attackers to execute arbitrary code via an Excel file with a malformed record with a modified length value, which leads to memory corruption."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:2000:sp3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:2003:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:2003:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:2004:*:mac:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:v.x:*:mac:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:xp:sp3:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:H/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "HIGH",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.1
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 4.9,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2006-03-14T23:02Z",
    "lastModifiedDate" : "2018-10-19T15:42Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0032",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "windows_2000",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  }, {
                    "version_value" : "resource_kit",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_2003_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "datacenter_edition",
                    "version_affected" : "="
                  }, {
                    "version_value" : "datacenter_edition_itanium",
                    "version_affected" : "="
                  }, {
                    "version_value" : "enterprise_64-bit",
                    "version_affected" : "="
                  }, {
                    "version_value" : "enterprise_edition",
                    "version_affected" : "="
                  }, {
                    "version_value" : "enterprise_edition_itanium",
                    "version_affected" : "="
                  }, {
                    "version_value" : "r2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "sp1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "standard",
                    "version_affected" : "="
                  }, {
                    "version_value" : "standard_64-bit",
                    "version_affected" : "="
                  }, {
                    "version_value" : "web",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_xp",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/21861",
          "name" : "21861",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1016826",
          "name" : "1016826",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.geocities.jp/ptrs_sec/advisory09e.html",
          "name" : "http://www.geocities.jp/ptrs_sec/advisory09e.html",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/108884",
          "name" : "VU#108884",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/446630/100/100/threaded",
          "name" : "SSRT061187",
          "refsource" : "HP",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/447509/100/0/threaded",
          "name" : "20061002 IE UXSS (Universal XSS in IE, was Re: Microsoft Internet Information Services UTF-7 XSS Vulnerability [MS06-053])",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/447511/100/0/threaded",
          "name" : "20061001 Microsoft Internet Information Services UTF-7 XSS Vulnerability [MS06-053]",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/19927",
          "name" : "19927",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA06-255A.html",
          "name" : "TA06-255A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/3564",
          "name" : "ADV-2006-3564",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-053",
          "name" : "MS06-053",
          "refsource" : "MS",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/28651",
          "name" : "ms-indexing-service-xss(28651)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A535",
          "name" : "oval:org.mitre.oval:def:535",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in the Indexing Service in Microsoft Windows 2000, XP, and Server 2003, when the Encoding option is set to Auto Select, allows remote attackers to inject arbitrary web script or HTML via a UTF-7 encoded URL, which is injected into an error message whose charset is set to UTF-7."
        }, {
          "lang" : "en",
          "value" : "Successful exploitation requires that the Indexing service is accessible through IIS."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2000:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2000:*:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2000:*:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2000:*:sp3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2000:*:sp4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2000:resource_kit:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:datacenter_edition:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:datacenter_edition:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:datacenter_edition:sp1_beta_1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:datacenter_edition_itanium:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:datacenter_edition_itanium:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:datacenter_edition_itanium:sp1_beta_1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:enterprise_64-bit:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:enterprise_edition:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:enterprise_edition:sp1_beta_1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:enterprise_edition_itanium:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:enterprise_edition_itanium:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:enterprise_edition_itanium:sp1_beta_1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:r2:*:datacenter_64-bit:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:sp1:*:enterprise:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:standard:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:standard:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:standard:sp1_beta_1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:standard_64-bit:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:web:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:web:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:web:sp1_beta_1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_xp:*:*:64-bit:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_xp:*:*:home:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_xp:*:*:media_center:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_xp:*:gold:professional:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_xp:*:sp1:home:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_xp:*:sp1:media_center:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_xp:*:sp2:home:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_xp:*:sp2:media_center:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_xp:*:sp2:tablet_pc:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2006-09-12T23:07Z",
    "lastModifiedDate" : "2019-04-30T14:27Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0033",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "office",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2000",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2003",
                    "version_affected" : "="
                  }, {
                    "version_value" : "xp",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/21013",
          "name" : "21013",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1016470",
          "name" : "1016470",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.fortinet.com/FortiGuardCenter/advisory/FG-2006-22.html",
          "name" : "http://www.fortinet.com/FortiGuardCenter/advisory/FG-2006-22.html",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/459388",
          "name" : "VU#459388",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.osvdb.org/27147",
          "name" : "27147",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/18913",
          "name" : "18913",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA06-192A.html",
          "name" : "TA06-192A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/2757",
          "name" : "ADV-2006-2757",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-039",
          "name" : "MS06-039",
          "refsource" : "MS",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A163",
          "name" : "oval:org.mitre.oval:def:163",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in Microsoft Office 2003 SP1 and SP2, Office XP SP3, Office 2000 SP3, and other products, allows user-assisted attackers to execute arbitrary code via a crafted PNG image that triggers memory corruption when it is parsed."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:2000:sp3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:2003:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:2003:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:xp:sp3:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2006-07-11T21:05Z",
    "lastModifiedDate" : "2018-10-12T21:38Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0034",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "distributed_transaction_coordinator",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_2000",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_2003_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "enterprise",
                    "version_affected" : "="
                  }, {
                    "version_value" : "enterprise_64-bit",
                    "version_affected" : "="
                  }, {
                    "version_value" : "r2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "standard",
                    "version_affected" : "="
                  }, {
                    "version_value" : "web",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_nt",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_xp",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://archives.neohapsis.com/archives/fulldisclosure/2006-05/0238.html",
          "name" : "20060509 [EEYEB20051011A] - Microsoft Distributed Transaction Coordinator Heap Overflow",
          "refsource" : "FULLDISC",
          "tags" : [ ]
        }, {
          "url" : "http://archives.neohapsis.com/archives/fulldisclosure/2006-05/0269.html",
          "name" : "20060510 Microsoft MSDTC NdrAllocate Validation Vulnerability",
          "refsource" : "FULLDISC",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/20000",
          "name" : "20000",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/863",
          "name" : "863",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1016047",
          "name" : "1016047",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.eeye.com/html/research/advisories/AD20060509a.html",
          "name" : "http://www.eeye.com/html/research/advisories/AD20060509a.html",
          "refsource" : "MISC",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/25335",
          "name" : "25335",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/433430/100/0/threaded",
          "name" : "20060509 [EEYEB20051011A] - Microsoft Distributed Transaction Coordinator Heap Overflow",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/433677/100/0/threaded",
          "name" : "20060511 Microsoft MSDTC NdrAllocate Validation Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/17906",
          "name" : "17906",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/1742",
          "name" : "ADV-2006-1742",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-018",
          "name" : "MS06-018",
          "refsource" : "MS",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/25559",
          "name" : "msdtc-network-message-dos(25559)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1222",
          "name" : "oval:org.mitre.oval:def:1222",
          "refsource" : "OVAL",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1477",
          "name" : "oval:org.mitre.oval:def:1477",
          "refsource" : "OVAL",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1908",
          "name" : "oval:org.mitre.oval:def:1908",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Heap-based buffer overflow in the CRpcIoManagerServer::BuildContext function in msdtcprx.dll for Microsoft Distributed Transaction Coordinator (MSDTC) for Windows NT 4.0 and Windows 2000 SP2 and SP3 allows remote attackers to execute arbitrary code via a long fifth argument to the BuildContextW or BuildContext opcode, which triggers a bug in the NdrAllocate function, aka the MSDTC Invalid Memory Access Vulnerability."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:distributed_transaction_coordinator:*:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2000:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2000:*:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2000:*:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2000:*:sp3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2000:*:sp4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:enterprise:*:64-bit:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:enterprise_64-bit:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:r2:*:64-bit:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:r2:*:datacenter_64-bit:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:standard:*:64-bit:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:web:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_nt:4.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_nt:4.0:*:enterprise_server:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_nt:4.0:*:server:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_nt:4.0:*:terminal_server:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_nt:4.0:*:workstation:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_nt:4.0:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_nt:4.0:sp1:enterprise_server:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_nt:4.0:sp1:server:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_nt:4.0:sp1:terminal_server:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_nt:4.0:sp1:workstation:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_nt:4.0:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_nt:4.0:sp2:enterprise_server:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_nt:4.0:sp2:server:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_nt:4.0:sp2:terminal_server:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_nt:4.0:sp2:workstation:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_nt:4.0:sp3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_nt:4.0:sp3:enterprise_server:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_nt:4.0:sp3:server:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_nt:4.0:sp3:terminal_server:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_nt:4.0:sp3:workstation:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_nt:4.0:sp4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_nt:4.0:sp4:enterprise_server:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_nt:4.0:sp4:server:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_nt:4.0:sp4:terminal_server:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_nt:4.0:sp4:workstation:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_nt:4.0:sp5:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_nt:4.0:sp5:enterprise_server:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_nt:4.0:sp5:server:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_nt:4.0:sp5:terminal_server:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_nt:4.0:sp5:workstation:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_nt:4.0:sp6:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_nt:4.0:sp6:enterprise_server:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_nt:4.0:sp6:server:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_nt:4.0:sp6:terminal_server:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_nt:4.0:sp6:workstation:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_nt:4.0:sp6a:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_nt:4.0:sp6a:enterprise_server:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_nt:4.0:sp6a:server:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_nt:4.0:sp6a:terminal_server:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_nt:4.0:sp6a:workstation:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_xp:*:*:64-bit:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_xp:*:*:embedded:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_xp:*:*:home:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_xp:*:*:media_center:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_xp:*:gold:professional:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_xp:*:sp1:64-bit:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_xp:*:sp1:embedded:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_xp:*:sp1:home:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_xp:*:sp1:media_center:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_xp:*:sp2:tablet_pc:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-05-10T02:14Z",
    "lastModifiedDate" : "2019-04-30T14:27Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0035",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "linux",
            "product" : {
              "product_data" : [ {
                "product_name" : "linux_kernel",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.6.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.15",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-399"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18482",
          "name" : "18482",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/388",
          "name" : "388",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=ad8e4b75c8a7bed475d72ce09bf5267188621961",
          "name" : "http://www.kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=ad8e4b75c8a7bed475d72ce09bf5267188621961",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16414",
          "name" : "16414",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.trustix.org/errata/2006/0004",
          "name" : "2006-0004",
          "refsource" : "TRUSTIX",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0220",
          "name" : "ADV-2006-0220",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24202",
          "name" : "kernel-afnetlink-dos(24202)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The netlink_rcv_skb function in af_netlink.c in Linux kernel 2.6.14 and 2.6.15 allows local users to cause a denial of service (infinite loop) via a nlmsg_len field of 0."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.14:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.15:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:N/I:N/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 4.9
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 3.9,
        "impactScore" : 6.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-11T21:03Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0036",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "linux",
            "product" : {
              "product_data" : [ {
                "product_name" : "linux_kernel",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.6.14",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commitdiff;h=15db34702cfafd24acc60295cf14861e497502ab",
          "name" : "http://kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commitdiff;h=15db34702cfafd24acc60295cf14861e497502ab",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18482",
          "name" : "18482",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/388",
          "name" : "388",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16414",
          "name" : "16414",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.trustix.org/errata/2006/0004",
          "name" : "2006-0004",
          "refsource" : "TRUSTIX",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0220",
          "name" : "ADV-2006-0220",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24203",
          "name" : "kernel-pptpincallrequest-dos(24203)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "ip_nat_pptp in the PPTP NAT helper (netfilter/ip_nat_helper_pptp.c) in Linux kernel 2.6.14, and other versions, allows remote attackers to cause a denial of service (memory corruption or crash) via an inbound PPTP_IN_CALL_REQUEST packet that causes a null pointer to be used in an offset calculation."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.14:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.8
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-23T22:03Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0037",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "linux",
            "product" : {
              "product_data" : [ {
                "product_name" : "linux_kernel",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.6.14",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commitdiff;h=03b9feca89366952ae5dfe4ad8107b1ece50b710",
          "name" : "http://kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commitdiff;h=03b9feca89366952ae5dfe4ad8107b1ece50b710",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18482",
          "name" : "18482",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/388",
          "name" : "388",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16414",
          "name" : "16414",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.trustix.org/errata/2006/0004",
          "name" : "2006-0004",
          "refsource" : "TRUSTIX",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0220",
          "name" : "ADV-2006-0220",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24204",
          "name" : "kernel-pptpnathelper-dos(24204)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "ip_nat_pptp in the PPTP NAT helper (netfilter/ip_nat_helper_pptp.c) in Linux kernel 2.6.14, and other versions, allows local users to cause a denial of service (memory corruption or crash) via a crafted outbound packet that causes an incorrect offset to be calculated from pointer arithmetic when non-linear SKBs (socket buffers) are used."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.14:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:N/I:N/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 4.9
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 3.9,
        "impactScore" : 6.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-23T22:03Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0038",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "linux",
            "product" : {
              "product_data" : [ {
                "product_name" : "linux_kernel",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.12.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.12.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.12.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.12.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.12.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.12.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.13.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.13.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.13.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.13.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.14.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.14.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.14.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.14.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.14.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.15.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.15.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.15.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.15.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.15.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.16",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6_test9_cvs",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-189"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/19330",
          "name" : "19330",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/20671",
          "name" : "20671",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/20716",
          "name" : "20716",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/20914",
          "name" : "20914",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/21465",
          "name" : "21465",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/22417",
          "name" : "22417",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://support.avaya.com/elmodocs2/security/ASA-2006-200.htm",
          "name" : "http://support.avaya.com/elmodocs2/security/ASA-2006-200.htm",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2006/dsa-1097",
          "name" : "DSA-1097",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2006/dsa-1103",
          "name" : "DSA-1103",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=ee4bb818ae35f68d1f848eae0a7b150a38eb4168",
          "name" : "http://www.kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=ee4bb818ae35f68d1f848eae0a7b150a38eb4168",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2006-0575.html",
          "name" : "RHSA-2006:0575",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/17178",
          "name" : "17178",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.ubuntu.com/usn/usn-302-1",
          "name" : "USN-302-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/1046",
          "name" : "ADV-2006-1046",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/2554",
          "name" : "ADV-2006-2554",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=186295",
          "name" : "https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=186295",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/25400",
          "name" : "linux-netfilter-doreplace-overflow(25400)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10945",
          "name" : "oval:org.mitre.oval:def:10945",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Integer overflow in the do_replace function in netfilter for Linux before 2.6.16-rc3, when using \"virtualization solutions\" such as OpenVZ, allows local users with CAP_NET_ADMIN rights to cause a buffer overflow in the copy_from_user function."
        }, {
          "lang" : "en",
          "value" : "Linux kernel version 2.6.16 has been released to address this issue."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.0:test1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.0:test10:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.0:test11:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.0:test2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.0:test3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.0:test4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.0:test5:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.0:test6:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.0:test7:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.0:test8:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.0:test9:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.1:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.1:rc2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.6:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.7:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.8:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.8:rc2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.8:rc3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.9:2.6.20:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.10:rc2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11:rc2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11:rc3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11:rc4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11.12:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.12:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.12:rc4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.12:rc5:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.12.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.12.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.12.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.12.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.12.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.12.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.13:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.13:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.13:rc4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.13:rc6:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.13:rc7:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.13.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.13.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.13.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.13.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.14:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.14:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.14:rc2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.14:rc3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.14:rc4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.14.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.14.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.14.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.14.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.14.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.15:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.15:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.15:rc2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.15:rc3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.15.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.15.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.15.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.15.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.15.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6_test9_cvs:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 6.9
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 3.4,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-03-22T20:06Z",
    "lastModifiedDate" : "2017-10-11T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0039",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "linux",
            "product" : {
              "product_data" : [ {
                "product_name" : "linux_kernel",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.6.16",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-362"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://bugs.gentoo.org/show_bug.cgi?id=133465",
          "name" : "http://bugs.gentoo.org/show_bug.cgi?id=133465",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.16.17",
          "name" : "http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.16.17",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/20185",
          "name" : "20185",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/20671",
          "name" : "20671",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/20914",
          "name" : "20914",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/20991",
          "name" : "20991",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/21476",
          "name" : "21476",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/22292",
          "name" : "22292",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/22945",
          "name" : "22945",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://support.avaya.com/elmodocs2/security/ASA-2006-249.htm",
          "name" : "http://support.avaya.com/elmodocs2/security/ASA-2006-249.htm",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2006/dsa-1097",
          "name" : "DSA-1097",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2006/dsa-1103",
          "name" : "DSA-1103",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=2722971cbe831117686039d5c334f2c0f560be13",
          "name" : "http://www.kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=2722971cbe831117686039d5c334f2c0f560be13",
          "refsource" : "MISC",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.osvdb.org/25697",
          "name" : "25697",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2006-0689.html",
          "name" : "RHSA-2006:0689",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/18113",
          "name" : "18113",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/usn-311-1",
          "name" : "USN-311-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/1893",
          "name" : "ADV-2006-1893",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/2554",
          "name" : "ADV-2006-2554",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=191698",
          "name" : "https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=191698",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/26583",
          "name" : "linux-doaddcounters-race-condition(26583)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10309",
          "name" : "oval:org.mitre.oval:def:10309",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Race condition in the do_add_counters function in netfilter for Linux kernel 2.6.16 allows local users with CAP_NET_ADMIN capabilities to read kernel memory by triggering the race condition in a way that produces a size value that is inconsistent with allocated memory, which leads to a buffer over-read in IPT_ENTRY_ITERATE."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:H/Au:N/C:P/I:N/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "HIGH",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 4.7
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 1.9,
        "impactScore" : 7.8,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-05-19T22:02Z",
    "lastModifiedDate" : "2017-10-11T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0040",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "gnome",
            "product" : {
              "product_data" : [ {
                "product_name" : "evolution",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.4.2.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/19094",
          "name" : "19094",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/426452/100/0/threaded",
          "name" : "20060301 Evolution Emailer DoS",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16899",
          "name" : "16899",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0801",
          "name" : "ADV-2006-0801",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/25050",
          "name" : "evolution-email-dos(25050)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "GNOME Evolution 2.4.2.1 and earlier allows remote attackers to cause a denial of service (CPU and memory consumption) via a text e-mail with a large number of URLs, possibly due to unknown problems in gtkhtml."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:gnome:evolution:2.4.2.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-03-10T01:02Z",
    "lastModifiedDate" : "2018-10-19T15:42Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0041",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ ]
        } ]
      },
      "references" : {
        "reference_data" : [ ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: none.  Reason: This candidate was withdrawn by its CNA.  Further investigation showed that it was not a security issue.  Notes: none."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ ]
    },
    "impact" : { },
    "publishedDate" : "2017-05-26T21:29Z",
    "lastModifiedDate" : "2017-05-26T21:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0042",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apache",
            "product" : {
              "product_data" : [ {
                "product_name" : "libapreq2",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.31",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.31_03",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.33",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.33",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.34",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.01_03",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.02_02",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.03_04",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.04_03",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.05",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.06",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "debian",
            "product" : {
              "product_data" : [ {
                "product_name" : "debian_linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18846",
          "name" : "18846",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Third Party Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/19139",
          "name" : "19139",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Third Party Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/19658",
          "name" : "19658",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/737",
          "name" : "737",
          "refsource" : "SREASON",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://svn.apache.org/viewcvs.cgi/httpd/apreq/tags/v2_07/CHANGES?rev=376998&view=markup",
          "name" : "http://svn.apache.org/viewcvs.cgi/httpd/apreq/tags/v2_07/CHANGES?rev=376998&view=markup",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.debian.org/security/2006/dsa-1000",
          "name" : "DSA-1000",
          "refsource" : "DEBIAN",
          "tags" : [ "Patch", "Third Party Advisory" ]
        }, {
          "url" : "http://www.gentoo.org/security/en/glsa/glsa-200604-08.xml",
          "name" : "GLSA-200604-08",
          "refsource" : "GENTOO",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16710",
          "name" : "16710",
          "refsource" : "BID",
          "tags" : [ "Patch", "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0645",
          "name" : "ADV-2006-0645",
          "refsource" : "VUPEN",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24917",
          "name" : "libapreq2-parsing-dos(24917)",
          "refsource" : "XF",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in (1) apreq_parse_headers and (2) apreq_parse_urlencoded functions in Apache2::Request (Libapreq2) before 2.07 allows remote attackers to cause a denial of service (CPU consumption) via unknown attack vectors that result in quadratic computational complexity."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:libapreq2:*:*:*:*:*:*:*:*",
          "versionEndExcluding" : "2.07"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:3.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:3.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-18T21:02Z",
    "lastModifiedDate" : "2018-11-29T15:45Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0043",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "suse",
            "product" : {
              "product_data" : [ {
                "product_name" : "suse_linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=350020",
          "name" : "http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=350020",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://lists.suse.com/archive/suse-security-announce/2006-Jan/0007.html",
          "name" : "SUSE-SA:2006:005",
          "refsource" : "SUSE",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18614",
          "name" : "18614",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18638",
          "name" : "18638",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18889",
          "name" : "18889",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2006/dsa-975",
          "name" : "DSA-975",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16388",
          "name" : "16388",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0348",
          "name" : "ADV-2006-0348",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24347",
          "name" : "nfs-rpcmountd-realpath-bo(24347)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Buffer overflow in the realpath function in nfs-server rpc.mountd, as used in SUSE Linux 9.1 through 10.0, allows local users to execute arbitrary code via unspecified vectors involving mount requests and symlinks."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:suse:suse_linux:1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:suse:suse_linux:9.1:*:personal:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:suse:suse_linux:9.1:*:professional:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:suse:suse_linux:9.1:*:x86_64:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:suse:suse_linux:9.2:*:personal:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:suse:suse_linux:9.2:*:professional:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:suse:suse_linux:9.2:*:x86_64:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:suse:suse_linux:9.3:*:personal:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:suse:suse_linux:9.3:*:professional:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:suse:suse_linux:9.3:*:x86_64:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:suse:suse_linux:10.0:*:professional:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 4.6
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 3.9,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-31T02:03Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0044",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "albatross",
            "product" : {
              "product_data" : [ {
                "product_name" : "albatross",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.00",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.01",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.20",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.30",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.32",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18457",
          "name" : "18457",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18496",
          "name" : "18496",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://security.debian.org/pool/updates/main/a/albatross/albatross_1.20-2.diff.gz",
          "name" : "http://security.debian.org/pool/updates/main/a/albatross/albatross_1.20-2.diff.gz",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2006/dsa-942",
          "name" : "DSA-942",
          "refsource" : "DEBIAN",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.object-craft.com.au/projects/albatross/news.html",
          "name" : "http://www.object-craft.com.au/projects/albatross/news.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/22451",
          "name" : "22451",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16252",
          "name" : "16252",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0196",
          "name" : "ADV-2006-0196",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24130",
          "name" : "albatross-context-command-execution(24130)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in context.py in Albatross web application toolkit before 1.33 allows remote attackers to execute arbitrary commands via unspecified vectors involving template files and the \"handling of submitted form fields\"."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:albatross:albatross:1.00:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:albatross:albatross:1.01:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:albatross:albatross:1.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:albatross:albatross:1.20:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:albatross:albatross:1.30:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:albatross:albatross:1.32:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-18T01:51Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0045",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "linley_henzell",
            "product" : {
              "product_data" : [ {
                "product_name" : "dungeon_crawl",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.0.0_b23",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18545",
          "name" : "18545",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18573",
          "name" : "18573",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2006/dsa-949",
          "name" : "DSA-949",
          "refsource" : "DEBIAN",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/22690",
          "name" : "22690",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16337",
          "name" : "16337",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0303",
          "name" : "ADV-2006-0303",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24262",
          "name" : "crawl-insecure-command-execution(24262)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "crawl before 4.0.0 does not securely call programs when saving and loading games, which allows local users to gain privileges."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:linley_henzell:dungeon_crawl:4.0.0_b23:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.2
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 3.9,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-20T21:03Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0046",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "cameron_simpson",
            "product" : {
              "product_data" : [ {
                "product_name" : "adzapper",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2006-01-01",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2006-01-05",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2006-01-07",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2006-01-14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2006-01-15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2006-01-23",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2006-01-24",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2006-01-25",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2006-01-28",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2006-01-29",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://adzapper.sourceforge.net/cvslog.html",
          "name" : "http://adzapper.sourceforge.net/cvslog.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://bugs.debian.org/cgi-bin/bugreport.cgi/squid_redirect.diff?bug=350308;msg=5;att=1",
          "name" : "http://bugs.debian.org/cgi-bin/bugreport.cgi/squid_redirect.diff?bug=350308;msg=5;att=1",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=350308",
          "name" : "http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=350308",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18771",
          "name" : "18771",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18777",
          "name" : "18777",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.debian.org/security/2006/dsa-966",
          "name" : "DSA-966",
          "refsource" : "DEBIAN",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/22900",
          "name" : "22900",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16558",
          "name" : "16558",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0491",
          "name" : "ADV-2006-0491",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24640",
          "name" : "adzapper-squid-redirect-dos(24640)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "squid_redirect script in adzapper before 2006-01-29 allows remote attackers to cause a denial of service (CPU consumption) via a URL with a large number of trailing / (forward slashes), which might produce inefficient regular expressions."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cameron_simpson:adzapper:2006-01-01:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cameron_simpson:adzapper:2006-01-05:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cameron_simpson:adzapper:2006-01-07:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cameron_simpson:adzapper:2006-01-14:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cameron_simpson:adzapper:2006-01-15:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cameron_simpson:adzapper:2006-01-23:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cameron_simpson:adzapper:2006-01-24:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cameron_simpson:adzapper:2006-01-25:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cameron_simpson:adzapper:2006-01-28:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cameron_simpson:adzapper:2006-01-29:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.8
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-13T11:06Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0047",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "freeciv",
            "product" : {
              "product_data" : [ {
                "product_name" : "freeciv",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.7a",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-399"
          }, {
            "lang" : "en",
            "value" : "CWE-20"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=355211",
          "name" : "http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=355211",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/19120",
          "name" : "19120",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/19227",
          "name" : "19227",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/19253",
          "name" : "19253",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.debian.org/security/2006/dsa-994",
          "name" : "DSA-994",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.gentoo.org/security/en/glsa/glsa-200603-11.xml",
          "name" : "GLSA-200603-11",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDKSA-2006:053",
          "name" : "MDKSA-2006:053",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/426866/100/0/threaded",
          "name" : "20060306 Out of memory crash in Freeciv 2.0.7",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16975",
          "name" : "16975",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0838",
          "name" : "ADV-2006-0838",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/25166",
          "name" : "freeciv-packets-dos(25166)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "packets.c in Freeciv 2.0 before 2.0.8 allows remote attackers to cause a denial of service (server crash) via crafted packets with negative compressed size values."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:freeciv:freeciv:2.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:freeciv:freeciv:2.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:freeciv:freeciv:2.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:freeciv:freeciv:2.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:freeciv:freeciv:2.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:freeciv:freeciv:2.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:freeciv:freeciv:2.0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:freeciv:freeciv:2.0.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:freeciv:freeciv:2.0.7a:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-03-07T11:02Z",
    "lastModifiedDate" : "2018-10-19T15:42Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0048",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "francesco_stablum",
            "product" : {
              "product_data" : [ {
                "product_name" : "tcpick",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.2.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://sourceforge.net/mailarchive/forum.php?thread_id=9989610&forum_id=37151",
          "name" : "http://sourceforge.net/mailarchive/forum.php?thread_id=9989610&forum_id=37151",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/17665",
          "name" : "17665",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/1466",
          "name" : "ADV-2006-1466",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/26090",
          "name" : "tcpick-writec-dos(26090)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Francesco Stablum tcpick 0.2.1 allows remote attackers to cause a denial of service (segmentation fault) via certain fragmented packets, possibly involving invalid headers and an attacker-controlled payload length.  NOTE: this issue might be a buffer overflow or overread."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:francesco_stablum:tcpick:0.2.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-04-26T00:06Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0049",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "gnu",
            "product" : {
              "product_data" : [ {
                "product_name" : "privacy_guard",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.3b",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.2.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "ftp://patches.sgi.com/support/free/security/advisories/20060401-01-U",
          "name" : "20060401-01-U",
          "refsource" : "SGI",
          "tags" : [ ]
        }, {
          "url" : "http://lists.gnupg.org/pipermail/gnupg-announce/2006q1/000216.html",
          "name" : "[gnupg-announce] 20060309 [Announce] GnuPG does not detect injection of unsigned data",
          "refsource" : "MLIST",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://lists.suse.de/archive/suse-security-announce/2006-Mar/0003.html",
          "name" : "SUSE-SA:2006:014",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/19173",
          "name" : "19173",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/19197",
          "name" : "19197",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/19203",
          "name" : "19203",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/19231",
          "name" : "19231",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/19232",
          "name" : "19232",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/19234",
          "name" : "19234",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/19244",
          "name" : "19244",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/19249",
          "name" : "19249",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/19287",
          "name" : "19287",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/19532",
          "name" : "19532",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/450",
          "name" : "450",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/568",
          "name" : "568",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1015749",
          "name" : "1015749",
          "refsource" : "SECTRACK",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.debian.org/security/2006/dsa-993",
          "name" : "DSA-993",
          "refsource" : "DEBIAN",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.gentoo.org/security/en/glsa/glsa-200603-08.xml",
          "name" : "GLSA-200603-08",
          "refsource" : "GENTOO",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDKSA-2006:055",
          "name" : "MDKSA-2006:055",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/23790",
          "name" : "23790",
          "refsource" : "OSVDB",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.redhat.com/archives/fedora-announce-list/2006-March/msg00021.html",
          "name" : "FEDORA-2006-147",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2006-0266.html",
          "name" : "RHSA-2006:0266",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/427324/100/0/threaded",
          "name" : "20060309 GnuPG does not detect injection of unsigned data",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/433931/100/0/threaded",
          "name" : "FLSA-2006:185355",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/17058",
          "name" : "17058",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.slackware.com/security/viewer.php?l=slackware-security&y=2006&m=slackware-security.476477",
          "name" : "SSA:2006-072-02",
          "refsource" : "SLACKWARE",
          "tags" : [ ]
        }, {
          "url" : "http://www.trustix.org/errata/2006/0014",
          "name" : "2006-0014",
          "refsource" : "TRUSTIX",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0915",
          "name" : "ADV-2006-0915",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/25184",
          "name" : "gnupg-nondetached-sig-verification(25184)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10063",
          "name" : "oval:org.mitre.oval:def:10063",
          "refsource" : "OVAL",
          "tags" : [ ]
        }, {
          "url" : "https://usn.ubuntu.com/264-1/",
          "name" : "USN-264-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "gpg in GnuPG before 1.4.2.2 does not properly verify non-detached signatures, which allows attackers to inject unsigned data via a data packet that is not associated with a control packet, which causes the check for concatenated signatures to report that the signature is valid, a different vulnerability than CVE-2006-0455."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:gnu:privacy_guard:1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:gnu:privacy_guard:1.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:gnu:privacy_guard:1.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:gnu:privacy_guard:1.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:gnu:privacy_guard:1.0.3b:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:gnu:privacy_guard:1.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:gnu:privacy_guard:1.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:gnu:privacy_guard:1.0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:gnu:privacy_guard:1.0.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:gnu:privacy_guard:1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:gnu:privacy_guard:1.2.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:gnu:privacy_guard:1.2.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:gnu:privacy_guard:1.2.2:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:gnu:privacy_guard:1.2.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:gnu:privacy_guard:1.2.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:gnu:privacy_guard:1.2.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:gnu:privacy_guard:1.2.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:gnu:privacy_guard:1.2.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:gnu:privacy_guard:1.3.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:gnu:privacy_guard:1.3.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:gnu:privacy_guard:1.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:gnu:privacy_guard:1.4.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:gnu:privacy_guard:1.4.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:gnu:privacy_guard:1.4.2.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-03-13T21:06Z",
    "lastModifiedDate" : "2018-10-19T15:42Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0050",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "debian",
            "product" : {
              "product_data" : [ {
                "product_name" : "debian_linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/19318",
          "name" : "19318",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.debian.org/security/2006/dsa-1013",
          "name" : "DSA-1013",
          "refsource" : "DEBIAN",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/17182",
          "name" : "17182",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/25442",
          "name" : "snmptrapfmt-log-temprary-file(25442)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "snmptrapfmt in Debian 3.0 allows local users to overwrite arbitrary files via a symlink attack on a temporary log file."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:3.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:3.0:*:alpha:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:3.0:*:arm:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:3.0:*:hppa:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:3.0:*:ia-32:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:3.0:*:ia-64:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:3.0:*:m68k:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:3.0:*:mips:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:3.0:*:mipsel:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:3.0:*:ppc:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:3.0:*:s-390:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:3.0:*:sparc:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:3.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:3.1:*:alpha:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:3.1:*:amd64:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:3.1:*:arm:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:3.1:*:hppa:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:3.1:*:ia-32:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:3.1:*:ia-64:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:3.1:*:m68k:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:3.1:*:mips:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:3.1:*:mipsel:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:3.1:*:ppc:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:3.1:*:s-390:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:3.1:*:sparc:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:H/Au:N/C:N/I:P/A:N",
          "accessVector" : "LOCAL",
          "accessComplexity" : "HIGH",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 1.2
        },
        "severity" : "LOW",
        "exploitabilityScore" : 1.9,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-03-23T11:06Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0051",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "kaffeine",
            "product" : {
              "product_data" : [ {
                "product_name" : "kaffeine_player",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.4.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.4.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.4.3b",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.5_rc1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.7.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/19525",
          "name" : "19525",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/19540",
          "name" : "19540",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/19542",
          "name" : "19542",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/19549",
          "name" : "19549",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/19557",
          "name" : "19557",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/19571",
          "name" : "19571",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1015863",
          "name" : "1015863",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2006/dsa-1023",
          "name" : "DSA-1023",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.gentoo.org/security/en/glsa/glsa-200604-04.xml",
          "name" : "GLSA-200604-04",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://www.kde.org/info/security/advisory-20060404-1.txt",
          "name" : "http://www.kde.org/info/security/advisory-20060404-1.txt",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDKSA-2006:065",
          "name" : "MDKSA-2006:065",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.novell.com/linux/security/advisories/2006_08_sr.html",
          "name" : "SUSE-SR:2006:008",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/430319/100/0/threaded",
          "name" : "20060405 [Kaffeine Security Advisory] Heap based buffer overflow in http_peek()",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/17372",
          "name" : "17372",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/1229",
          "name" : "ADV-2006-1229",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/25631",
          "name" : "kaffeine-http-peek-bo(25631)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://usn.ubuntu.com/268-1/",
          "name" : "USN-268-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Buffer overflow in playlistimport.cpp in Kaffeine Player 0.4.2 through 0.7.1 allows user-assisted attackers to execute arbitrary code via long HTTP request headers when Kaffeine is \"fetching remote playlists\", which triggers the overflow in the http_peek function."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:kaffeine:kaffeine_player:0.4.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:kaffeine:kaffeine_player:0.4.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:kaffeine:kaffeine_player:0.4.3b:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:kaffeine:kaffeine_player:0.5_rc1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:kaffeine:kaffeine_player:0.7.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:H/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "HIGH",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.1
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 4.9,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2006-04-05T10:04Z",
    "lastModifiedDate" : "2018-10-19T15:42Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0052",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "gnu",
            "product" : {
              "product_data" : [ {
                "product_name" : "mailman",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.1.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.1.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.1b1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "ftp://patches.sgi.com/support/free/security/advisories/20060602-01-U.asc",
          "name" : "20060602-01-U",
          "refsource" : "SGI",
          "tags" : [ ]
        }, {
          "url" : "http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=358892",
          "name" : "http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=358892",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://secunia.com/advisories/19522",
          "name" : "19522",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/19545",
          "name" : "19545",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/19571",
          "name" : "19571",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/20624",
          "name" : "20624",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/20782",
          "name" : "20782",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1015851",
          "name" : "1015851",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2006/dsa-1027",
          "name" : "DSA-1027",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDKSA-2006:061",
          "name" : "MDKSA-2006:061",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.novell.com/linux/security/advisories/2006_08_sr.html",
          "name" : "SUSE-SR:2006:008",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/24367",
          "name" : "24367",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2006-0486.html",
          "name" : "RHSA-2006:0486",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/17311",
          "name" : "17311",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9475",
          "name" : "oval:org.mitre.oval:def:9475",
          "refsource" : "OVAL",
          "tags" : [ ]
        }, {
          "url" : "https://usn.ubuntu.com/267-1/",
          "name" : "USN-267-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The attachment scrubber (Scrubber.py) in Mailman 2.1.5 and earlier, when using Python's library email module 2.5, allows remote attackers to cause a denial of service (mailing list delivery failure) via a multipart MIME message with a single part that has two blank lines between the first boundary and the end boundary."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:gnu:mailman:1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:gnu:mailman:1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:gnu:mailman:2.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:gnu:mailman:2.0:beta3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:gnu:mailman:2.0:beta4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:gnu:mailman:2.0:beta5:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:gnu:mailman:2.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:gnu:mailman:2.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:gnu:mailman:2.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:gnu:mailman:2.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:gnu:mailman:2.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:gnu:mailman:2.0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:gnu:mailman:2.0.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:gnu:mailman:2.0.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:gnu:mailman:2.0.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:gnu:mailman:2.0.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:gnu:mailman:2.0.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:gnu:mailman:2.0.12:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:gnu:mailman:2.0.13:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:gnu:mailman:2.0.14:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:gnu:mailman:2.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:gnu:mailman:2.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:gnu:mailman:2.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:gnu:mailman:2.1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:gnu:mailman:2.1.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:gnu:mailman:2.1.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:gnu:mailman:2.1b1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-03-31T11:06Z",
    "lastModifiedDate" : "2018-10-03T21:34Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0053",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "tony_cook",
            "product" : {
              "product_data" : [ {
                "product_name" : "imager",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.41",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.42",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.43",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.44_1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.45",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.45_2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.47",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.48",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.49",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-399"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=359661",
          "name" : "http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=359661",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://rt.cpan.org/Public/Bug/Display.html?id=18397",
          "name" : "http://rt.cpan.org/Public/Bug/Display.html?id=18397",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/19575",
          "name" : "19575",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/19577",
          "name" : "19577",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.debian.org/security/2006/dsa-1028",
          "name" : "DSA-1028",
          "refsource" : "DEBIAN",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/17415",
          "name" : "17415",
          "refsource" : "BID",
          "tags" : [ "Exploit", "Patch" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/1294",
          "name" : "ADV-2006-1294",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/25717",
          "name" : "imager-jpeg-tga-dos(25717)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Imager (libimager-perl) before 0.50 allows user-assisted attackers to cause a denial of service (segmentation fault) by writing a 2- or 4-channel JPEG image (or a 2-channel TGA image) to a scalar, which triggers a NULL pointer dereference."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tony_cook:imager:0.41:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tony_cook:imager:0.42:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tony_cook:imager:0.43:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tony_cook:imager:0.44_1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tony_cook:imager:0.45:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tony_cook:imager:0.45_2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tony_cook:imager:0.47:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tony_cook:imager:0.48:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tony_cook:imager:0.49:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:H/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "HIGH",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 2.6
        },
        "severity" : "LOW",
        "exploitabilityScore" : 4.9,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2006-04-10T18:06Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0054",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "freebsd",
            "product" : {
              "product_data" : [ {
                "product_name" : "freebsd",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-06:04.ipfw.asc",
          "name" : "FreeBSD-SA-06:04",
          "refsource" : "FREEBSD",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18378",
          "name" : "18378",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1015477",
          "name" : "1015477",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/22319",
          "name" : "22319",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16209",
          "name" : "16209",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24073",
          "name" : "ipfw-icmp-fragment-dos(24073)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The ipfw firewall in FreeBSD 6.0-RELEASE allows remote attackers to cause a denial of service (firewall crash) via ICMP IP fragments that match a reset, reject or unreach action, which leads to an access of an uninitialized pointer."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:freebsd:freebsd:6.0:release:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:freebsd:freebsd:6.0:stable:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-11T21:03Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0055",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "freebsd",
            "product" : {
              "product_data" : [ {
                "product_name" : "freebsd",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.2.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-06:02.ee.asc",
          "name" : "FreeBSD-SA-06:02",
          "refsource" : "FREEBSD",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18404",
          "name" : "18404",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1015469",
          "name" : "1015469",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/22320",
          "name" : "22320",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16207",
          "name" : "16207",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24074",
          "name" : "ee-ispell-op-symlink(24074)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The ispell_op function in ee on FreeBSD 4.10 to 6.0 uses predictable filenames and does not confirm which file is being written, which allows local users to overwrite arbitrary files via a symlink attack when ee invokes ispell."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:freebsd:freebsd:4.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:freebsd:freebsd:4.10:release:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:freebsd:freebsd:4.10:release_p8:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:freebsd:freebsd:4.10:releng:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:freebsd:freebsd:4.11:release_p3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:freebsd:freebsd:4.11:releng:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:freebsd:freebsd:4.11:stable:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:freebsd:freebsd:5.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:freebsd:freebsd:5.0:alpha:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:freebsd:freebsd:5.0:release_p14:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:freebsd:freebsd:5.0:releng:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:freebsd:freebsd:5.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:freebsd:freebsd:5.1:alpha:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:freebsd:freebsd:5.1:release:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:freebsd:freebsd:5.1:release_p5:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:freebsd:freebsd:5.1:releng:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:freebsd:freebsd:5.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:freebsd:freebsd:5.2.1:release:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:freebsd:freebsd:5.2.1:releng:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:freebsd:freebsd:5.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:freebsd:freebsd:5.3:release:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:freebsd:freebsd:5.3:releng:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:freebsd:freebsd:5.3:stable:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:freebsd:freebsd:5.4:pre-release:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:freebsd:freebsd:5.4:release:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:freebsd:freebsd:5.4:releng:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:freebsd:freebsd:6.0:release:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:freebsd:freebsd:6.0:stable:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:N/I:P/A:N",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 2.1
        },
        "severity" : "LOW",
        "exploitabilityScore" : 3.9,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-11T21:03Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0056",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "pam-mysql",
            "product" : {
              "product_data" : [ {
                "product_name" : "pam-mysql",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.4.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.7_pre1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.7_pre2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://jvn.jp/cert/JVNVU%23693909/index.html",
          "name" : "http://jvn.jp/cert/JVNVU%23693909/index.html",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18598",
          "name" : "18598",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/20690",
          "name" : "20690",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1015603",
          "name" : "1015603",
          "refsource" : "SECTRACK",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://sourceforge.net/forum/forum.php?forum_id=499394",
          "name" : "http://sourceforge.net/forum/forum.php?forum_id=499394",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.gentoo.org/security/en/glsa/glsa-200606-18.xml",
          "name" : "GLSA-200606-18",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/693909",
          "name" : "VU#693909",
          "refsource" : "CERT-VN",
          "tags" : [ "Patch", "Third Party Advisory", "US Government Resource" ]
        }, {
          "url" : "http://www.osvdb.org/22994",
          "name" : "22994",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/22995",
          "name" : "22995",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16564",
          "name" : "16564",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0490",
          "name" : "ADV-2006-0490",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Double free vulnerability in the authentication and authentication token alteration code in PAM-MySQL 0.6.x before 0.6.2 and 0.7.x before 0.7pre3 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via crafted passwords, which lead to a double free of a pointer that was created by the pam_get_item function.  NOTE: this issue only occurs in certain configurations in which there are multiple PAM modules, PAM-MySQL is not evaluated first, and there are no requisite modules before PAM-MySQL."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pam-mysql:pam-mysql:0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pam-mysql:pam-mysql:0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pam-mysql:pam-mysql:0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pam-mysql:pam-mysql:0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pam-mysql:pam-mysql:0.4.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pam-mysql:pam-mysql:0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pam-mysql:pam-mysql:0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pam-mysql:pam-mysql:0.7_pre1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pam-mysql:pam-mysql:0.7_pre2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-13T11:06Z",
    "lastModifiedDate" : "2011-03-08T02:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0057",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "ie",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.01",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.kb.cert.org/vuls/id/998297",
          "name" : "VU#998297",
          "refsource" : "CERT-VN",
          "tags" : [ "Third Party Advisory", "US Government Resource" ]
        }, {
          "url" : "http://www.microsoft.com/technet/security/bulletin/ms05-054.mspx",
          "name" : "http://www.microsoft.com/technet/security/bulletin/ms05-054.mspx",
          "refsource" : "MISC",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/23657",
          "name" : "23657",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16409",
          "name" : "16409",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24379",
          "name" : "ie-activex-killbit-bypass(24379)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to bypass the Kill bit settings for dangerous ActiveX controls via unknown vectors involving crafted HTML, which can expose the browser to attacks that would otherwise be prevented by the Kill bit setting. NOTE: CERT/CC claims that MS05-054 fixes this issue, but it is not described in MS05-054."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:ie:5.01:sp4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:ie:5.5:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:ie:6:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:ie:6:windows_server_2003_sp1:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-27T22:03Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0058",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "sendmail",
            "product" : {
              "product_data" : [ {
                "product_name" : "sendmail",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.13.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.13.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.13.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.13.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.13.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.13.5",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-06:13.sendmail.asc",
          "name" : "FreeBSD-SA-06:13",
          "refsource" : "FREEBSD",
          "tags" : [ ]
        }, {
          "url" : "ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2006-010.txt.asc",
          "name" : "NetBSD-SA2006-010",
          "refsource" : "NETBSD",
          "tags" : [ ]
        }, {
          "url" : "ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2006.24/SCOSA-2006.24.txt",
          "name" : "SCOSA-2006.24",
          "refsource" : "SCO",
          "tags" : [ ]
        }, {
          "url" : "ftp://patches.sgi.com/support/free/security/advisories/20060302-01-P",
          "name" : "20060302-01-P",
          "refsource" : "SGI",
          "tags" : [ ]
        }, {
          "url" : "ftp://patches.sgi.com/support/free/security/advisories/20060401-01-U",
          "name" : "20060401-01-U",
          "refsource" : "SGI",
          "tags" : [ ]
        }, {
          "url" : "http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&cc=us&objectID=c00629555",
          "name" : "HPSBUX02108",
          "refsource" : "HP",
          "tags" : [ ]
        }, {
          "url" : "http://itrc.hp.com/service/cki/docDisplay.do?docId=c00692635",
          "name" : "HPSBTU02116",
          "refsource" : "HP",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/19342",
          "name" : "19342",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/19345",
          "name" : "19345",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/19346",
          "name" : "19346",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/19349",
          "name" : "19349",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/19356",
          "name" : "19356",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/19360",
          "name" : "19360",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/19361",
          "name" : "19361",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/19363",
          "name" : "19363",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/19367",
          "name" : "19367",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/19368",
          "name" : "19368",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/19394",
          "name" : "19394",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/19404",
          "name" : "19404",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/19407",
          "name" : "19407",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/19450",
          "name" : "19450",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/19466",
          "name" : "19466",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/19532",
          "name" : "19532",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/19533",
          "name" : "19533",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/19676",
          "name" : "19676",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/19774",
          "name" : "19774",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/20243",
          "name" : "20243",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/20723",
          "name" : "20723",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/612",
          "name" : "612",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/743",
          "name" : "743",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1015801",
          "name" : "1015801",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://slackware.com/security/viewer.php?l=slackware-security&y=2006&m=slackware-security.619600",
          "name" : "SSA:2006-081-01",
          "refsource" : "SLACKWARE",
          "tags" : [ ]
        }, {
          "url" : "http://sunsolve.sun.com/search/document.do?assetkey=1-26-102262-1",
          "name" : "102262",
          "refsource" : "SUNALERT",
          "tags" : [ ]
        }, {
          "url" : "http://sunsolve.sun.com/search/document.do?assetkey=1-26-102324-1",
          "name" : "102324",
          "refsource" : "SUNALERT",
          "tags" : [ ]
        }, {
          "url" : "http://sunsolve.sun.com/search/document.do?assetkey=1-66-200494-1",
          "name" : "200494",
          "refsource" : "SUNALERT",
          "tags" : [ ]
        }, {
          "url" : "http://support.avaya.com/elmodocs2/security/ASA-2006-074.htm",
          "name" : "http://support.avaya.com/elmodocs2/security/ASA-2006-074.htm",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://support.avaya.com/elmodocs2/security/ASA-2006-078.htm",
          "name" : "http://support.avaya.com/elmodocs2/security/ASA-2006-078.htm",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.ciac.org/ciac/bulletins/q-151.shtml",
          "name" : "Q-151",
          "refsource" : "CIAC",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2006/dsa-1015",
          "name" : "DSA-1015",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.f-secure.com/security/fsc-2006-2.shtml",
          "name" : "http://www.f-secure.com/security/fsc-2006-2.shtml",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.gentoo.org/security/en/glsa/glsa-200603-21.xml",
          "name" : "GLSA-200603-21",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://www.iss.net/threats/216.html",
          "name" : "20060322 Sendmail Remote Signal Handling Vulnerability",
          "refsource" : "ISS",
          "tags" : [ ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/834865",
          "name" : "VU#834865",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDKSA-2006:058",
          "name" : "MDKSA-2006:058",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.novell.com/linux/security/advisories/2006_17_sendmail.html",
          "name" : "SUSE-SA:2006:017",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://www.openbsd.org/errata38.html#sendmail",
          "name" : "[3.8] 006: SECURITY FIX: March 25, 2006",
          "refsource" : "OPENBSD",
          "tags" : [ ]
        }, {
          "url" : "http://www.openpkg.org/security/advisories/OpenPKG-SA-2006.007-sendmail.html",
          "name" : "OpenPKG-SA-2006.007",
          "refsource" : "OPENPKG",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/24037",
          "name" : "24037",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/archives/fedora-announce-list/2006-April/msg00017.html",
          "name" : "FEDORA-2006-194",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/archives/fedora-announce-list/2006-April/msg00018.html",
          "name" : "FEDORA-2006-193",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2006-0264.html",
          "name" : "RHSA-2006:0264",
          "refsource" : "REDHAT",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2006-0265.html",
          "name" : "RHSA-2006:0265",
          "refsource" : "REDHAT",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/428536/100/0/threaded",
          "name" : "20060322 sendmail vuln advisories (CVE-2006-0058)",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/428656/100/0/threaded",
          "name" : "FLSA:186277",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/17192",
          "name" : "17192",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.sendmail.com/company/advisory/index.shtml",
          "name" : "http://www.sendmail.com/company/advisory/index.shtml",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA06-081A.html",
          "name" : "TA06-081A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/1049",
          "name" : "ADV-2006-1049",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/1051",
          "name" : "ADV-2006-1051",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/1068",
          "name" : "ADV-2006-1068",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/1072",
          "name" : "ADV-2006-1072",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/1139",
          "name" : "ADV-2006-1139",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/1157",
          "name" : "ADV-2006-1157",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/1529",
          "name" : "ADV-2006-1529",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/2189",
          "name" : "ADV-2006-2189",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/2490",
          "name" : "ADV-2006-2490",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www-1.ibm.com/support/search.wss?rs=0&q=IY82992&apar=only",
          "name" : "IY82992",
          "refsource" : "AIXAPAR",
          "tags" : [ ]
        }, {
          "url" : "http://www-1.ibm.com/support/search.wss?rs=0&q=IY82993&apar=only",
          "name" : "IY82993",
          "refsource" : "AIXAPAR",
          "tags" : [ ]
        }, {
          "url" : "http://www-1.ibm.com/support/search.wss?rs=0&q=IY82994&apar=only",
          "name" : "IY82994",
          "refsource" : "AIXAPAR",
          "tags" : [ ]
        }, {
          "url" : "http://www14.software.ibm.com/webapp/set2/sas/f/hmc/power5/install/v52.Readme.html#MH00688",
          "name" : "http://www14.software.ibm.com/webapp/set2/sas/f/hmc/power5/install/v52.Readme.html#MH00688",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www14.software.ibm.com/webapp/set2/subscriptions/pqvcmjd?mode=18&ID=2751",
          "name" : "http://www14.software.ibm.com/webapp/set2/subscriptions/pqvcmjd?mode=18&ID=2751",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24584",
          "name" : "smtp-timeout-bo(24584)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11074",
          "name" : "oval:org.mitre.oval:def:11074",
          "refsource" : "OVAL",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1689",
          "name" : "oval:org.mitre.oval:def:1689",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Signal handler race condition in Sendmail 8.13.x before 8.13.6 allows remote attackers to execute arbitrary code by triggering timeouts in a way that causes the setjmp and longjmp function calls to be interrupted and modify unexpected memory locations."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sendmail:sendmail:8.13.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sendmail:sendmail:8.13.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sendmail:sendmail:8.13.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sendmail:sendmail:8.13.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sendmail:sendmail:8.13.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sendmail:sendmail:8.13.5:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:H/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "HIGH",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.6
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 4.9,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-03-22T20:06Z",
    "lastModifiedDate" : "2018-10-19T15:42Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0059",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "livedata",
            "product" : {
              "product_data" : [ {
                "product_name" : "iccp_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.00.045",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/20146",
          "name" : "20146",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1016113",
          "name" : "1016113",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.digitalbond.com/SCADA_Blog/2006/05/us-cert-livedata-iccp-vulnerability.html",
          "name" : "http://www.digitalbond.com/SCADA_Blog/2006/05/us-cert-livedata-iccp-vulnerability.html",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/190617",
          "name" : "VU#190617",
          "refsource" : "CERT-VN",
          "tags" : [ "Patch", "US Government Resource" ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/JGEI-6MMS9T",
          "name" : "http://www.kb.cert.org/vuls/id/JGEI-6MMS9T",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/18010",
          "name" : "18010",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/1830",
          "name" : "ADV-2006-1830",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/26490",
          "name" : "livedata-iccp-rfc1006-bo(26490)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Heap-based buffer overflow in the ISO Transport Service over TCP (RFC 1006) implementation of LiveData ICCP Server before 5.00.035 allows remote attackers to cause a denial of service or execute arbitrary code via malformed packets."
        }, {
          "lang" : "en",
          "value" : "This vulnerability is addressed in the following product release:\r\nLiveData, ICCP Server, 5.00.035"
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:livedata:iccp_server:5.00.045:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-05-19T19:02Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0061",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "sillycycle",
            "product" : {
              "product_data" : [ {
                "product_name" : "xlockmore",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.22",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-306"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=318123",
          "name" : "https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=318123",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Patch", "Third Party Advisory" ]
        }, {
          "url" : "https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=399003",
          "name" : "https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=399003",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Third Party Advisory" ]
        }, {
          "url" : "https://security-tracker.debian.org/tracker/CVE-2006-0061",
          "name" : "https://security-tracker.debian.org/tracker/CVE-2006-0061",
          "refsource" : "MISC",
          "tags" : [ "Third Party Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "xlockmore 5.13 and 5.22 segfaults when using libpam-opensc and returns the underlying xsession. This allows unauthorized users access to the X session."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sillycycle:xlockmore:5.13:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sillycycle:xlockmore:5.22:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "acInsufInfo" : false,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2019-11-06T02:15Z",
    "lastModifiedDate" : "2019-11-08T18:51Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0062",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "sillycycle",
            "product" : {
              "product_data" : [ {
                "product_name" : "xlockmore",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.13",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-306"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=309760",
          "name" : "https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=309760",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Patch", "Third Party Advisory" ]
        }, {
          "url" : "https://security-tracker.debian.org/tracker/CVE-2006-0062",
          "name" : "https://security-tracker.debian.org/tracker/CVE-2006-0062",
          "refsource" : "MISC",
          "tags" : [ "Third Party Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "xlockmore 5.13 allows potential xlock bypass when FVWM switches to the same virtual desktop as a new Gaim window."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sillycycle:xlockmore:5.13:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "acInsufInfo" : false,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2019-11-06T03:15Z",
    "lastModifiedDate" : "2019-11-06T18:40Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0063",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "phpbb_group",
            "product" : {
              "product_data" : [ {
                "product_name" : "phpbb",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0.19",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://securityreason.com/achievement_securityalert/30",
          "name" : "20060105 phpBB 2.0.19 XSS",
          "refsource" : "SREASONRES",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/313",
          "name" : "313",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/22672",
          "name" : "22672",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0051",
          "name" : "ADV-2006-0051",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in phpBB 2.0.19, when \"Allowed HTML tags\" is enabled, allows remote attackers to inject arbitrary web script or HTML via a permitted HTML tag with ' (single quote) characters and active attributes such as onmouseover, a variant of CVE-2005-4357."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:phpbb_group:phpbb:2.0.19:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-05T19:03Z",
    "lastModifiedDate" : "2011-03-07T05:00Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0064",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "devellion",
            "product" : {
              "product_data" : [ {
                "product_name" : "cubecart",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-94"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.vupen.com/english/advisories/2006/0016",
          "name" : "ADV-2006-0016",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/1398",
          "name" : "1398",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "PHP remote file include vulnerability in includes/orderSuccess.inc.php in CubeCart allows remote attackers to execute arbitrary PHP code via a URL in the glob[rootDir] parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:devellion:cubecart:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-03T22:03Z",
    "lastModifiedDate" : "2017-10-19T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0065",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "vego",
            "product" : {
              "product_data" : [ {
                "product_name" : "vego_web_forum",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.26",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://evuln.com/vulns/1/summary.html",
          "name" : "http://evuln.com/vulns/1/summary.html",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18273",
          "name" : "18273",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/315",
          "name" : "315",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/22140",
          "name" : "22140",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/420661/100/0/threaded",
          "name" : "20060101 [eVuln] VEGO Web Forum SQL Injection Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16107",
          "name" : "16107",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0003",
          "name" : "ADV-2006-0003",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in (1) functions.php, (2) functions_update.php, and (3) functions_display.php in VEGO Web Forum 1.26 and earlier allows remote attackers to execute arbitrary SQL commands via the theme_id parameter in index.php."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:vego:vego_web_forum:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.26"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-03T22:03Z",
    "lastModifiedDate" : "2018-10-19T15:42Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0066",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "phpjournaler",
            "product" : {
              "product_data" : [ {
                "product_name" : "phpjournaler",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://evuln.com/vulns/9/summary.html",
          "name" : "http://evuln.com/vulns/9/summary.html",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18265",
          "name" : "18265",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/22149",
          "name" : "22149",
          "refsource" : "OSVDB",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/420666/100/0/threaded",
          "name" : "20060101 [eVuln] PHPjournaler SQL Injection Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16111",
          "name" : "16111",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0006",
          "name" : "ADV-2006-0006",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in index.php in PHPjournaler 1.0 allows remote attackers to execute arbitrary SQL commands via the readold parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:phpjournaler:phpjournaler:1.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-03T22:03Z",
    "lastModifiedDate" : "2018-10-19T15:42Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0067",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "vego",
            "product" : {
              "product_data" : [ {
                "product_name" : "vego_links_builder",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.00",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://evuln.com/vulns/2/summary.html",
          "name" : "http://evuln.com/vulns/2/summary.html",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18272",
          "name" : "18272",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/22139",
          "name" : "22139",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16108",
          "name" : "16108",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0004",
          "name" : "ADV-2006-0004",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in login.php in VEGO Links Builder 2.00 and earlier allows remote attackers to execute arbitrary SQL commands via the username parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:vego:vego_links_builder:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "2.00"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-03T22:03Z",
    "lastModifiedDate" : "2011-03-08T02:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0068",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "primo_place",
            "product" : {
              "product_data" : [ {
                "product_name" : "primo_cart",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://pridels0.blogspot.com/2006/01/primo-cart-sql-inj.html",
          "name" : "http://pridels0.blogspot.com/2006/01/primo-cart-sql-inj.html",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18264",
          "name" : "18264",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/22146",
          "name" : "22146",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/22147",
          "name" : "22147",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16125",
          "name" : "16125",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0008",
          "name" : "ADV-2006-0008",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in Primo Cart 1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) q parameter to search.php and (2) email parameter to user.php."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:primo_place:primo_cart:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.0"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-03T23:03Z",
    "lastModifiedDate" : "2011-03-08T02:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0069",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "chipmunk_scripts",
            "product" : {
              "product_data" : [ {
                "product_name" : "chipmunk_guestbook",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.4",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://evuln.com/vulns/4/summary.html",
          "name" : "http://evuln.com/vulns/4/summary.html",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18270",
          "name" : "18270",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/420667/100/0/threaded",
          "name" : "20060101 [eVuln] Chipmunk Guestbook XSS Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16112",
          "name" : "16112",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/19087",
          "name" : "19087",
          "refsource" : "BID",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in addentry.php in Chipmunk Guestbook 1.4 and earlier allows remote attackers to inject arbitrary web script or HTML via the homepage parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:chipmunk_scripts:chipmunk_guestbook:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.4"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-03T23:03Z",
    "lastModifiedDate" : "2018-10-19T15:42Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0070",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "drupal",
            "product" : {
              "product_data" : [ {
                "product_name" : "drupal",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.5.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.6.4",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/archive/1/420671/100/0/threaded",
          "name" : "20060102 Drupal all versiyon xss cehennem.org",
          "refsource" : "BUGTRAQ",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/420683/100/0/threaded",
          "name" : "20060103 Re: Drupal all versiyon xss cehennem.org",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "** DISPUTED **  Drupal allows remote attackers to conduct cross-site scripting (XSS) attacks via an IMG tag with an unusual encoded Javascript function name, as demonstrated using variations of the alert() function.  NOTE: a followup by the vendor suggests that the issue does not exist in 4.5.6 or 4.6.4 when \"Filtered HTML\" is enabled, and since \"Full HTML\" would not filter HTML by design, perhaps this should not be included in CVE."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:4.5.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:drupal:drupal:4.6.4:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-04T00:03Z",
    "lastModifiedDate" : "2018-10-19T15:42Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0071",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "gentoo",
            "product" : {
              "product_data" : [ {
                "product_name" : "app-crypt_pinentry",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.7.2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18284",
          "name" : "18284",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.gentoo.org/security/en/glsa/glsa-200601-01.xml",
          "name" : "GLSA-200601-01",
          "refsource" : "GENTOO",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/22211",
          "name" : "22211",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16120",
          "name" : "16120",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The ebuild for pinentry before 0.7.2-r2 on Gentoo Linux sets setgid bits for pinentry programs, which allows local users to read or overwrite arbitrary files as gid 0."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:gentoo:app-crypt_pinentry:0.7.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:gentoo:app-crypt_pinentry:0.7.2:r1:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:gentoo:linux:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:C/I:C/A:N",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "NONE",
          "baseScore" : 6.6
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 3.9,
        "impactScore" : 9.2,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-04T00:03Z",
    "lastModifiedDate" : "2008-09-05T20:58Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0072",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "sco",
            "product" : {
              "product_data" : [ {
                "product_name" : "openserver",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.6a",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.7",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://downloads.securityfocus.com/vulnerabilities/exploits/Openserver_bof.c",
          "name" : "http://downloads.securityfocus.com/vulnerabilities/exploits/Openserver_bof.c",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/420677",
          "name" : "20060102 SCO Openserver 5.0.x exploit",
          "refsource" : "BUGTRAQ",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16122",
          "name" : "16122",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Buffer overflow in termsh on SCO OpenServer 5.0.7 allows remote attackers to execute arbitrary code via a long -o command line argument.  NOTE: this is probably a different vulnerability than CVE-2005-0351 since it involves a distinct attack vector."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:sco:openserver:5.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:sco:openserver:5.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:sco:openserver:5.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:sco:openserver:5.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:sco:openserver:5.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:sco:openserver:5.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:sco:openserver:5.0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:sco:openserver:5.0.6a:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:sco:openserver:5.0.7:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-04T00:03Z",
    "lastModifiedDate" : "2008-09-05T20:58Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0073",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "discusware",
            "product" : {
              "product_data" : [ {
                "product_name" : "discus_freeware",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.10.5",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "discus_professional",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.10.4",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18283",
          "name" : "18283",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/22153",
          "name" : "22153",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16119",
          "name" : "16119",
          "refsource" : "BID",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in DiscusWare Discus Freeware 3.10.5 and Professional 3.10.4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors in a URL, which is not properly sanitized from the resulting error message.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:discusware:discus_freeware:3.10.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:discusware:discus_professional:3.10.4:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-04T00:03Z",
    "lastModifiedDate" : "2008-09-05T20:58Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0074",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "jevontech",
            "product" : {
              "product_data" : [ {
                "product_name" : "phpenpals",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.1",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://evuln.com/vulns/5/summary.html",
          "name" : "http://evuln.com/vulns/5/summary.html",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18269",
          "name" : "18269",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/22150",
          "name" : "22150",
          "refsource" : "OSVDB",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/420690/100/0/threaded",
          "name" : "20060101 [eVuln] PHPenpals SQL Injection Vulnerabilit",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16109",
          "name" : "16109",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0005",
          "name" : "ADV-2006-0005",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/8706",
          "name" : "8706",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in profile.php in PHPenpals allows remote attackers to execute arbitrary SQL commands via the personalID parameter.  NOTE: it was later reported that 1.1 and earlier are affected."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:jevontech:phpenpals:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.1"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-04T01:03Z",
    "lastModifiedDate" : "2018-10-19T15:42Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0075",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "gnu",
            "product" : {
              "product_data" : [ {
                "product_name" : "phpbook",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.2",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://evuln.com/vulns/6/summary.html",
          "name" : "http://evuln.com/vulns/6/summary.html",
          "refsource" : "MISC",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://secunia.com/advisories/18268",
          "name" : "18268",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/420698/100/0/threaded",
          "name" : "20060101 [eVuln] phpBook PHP Code Execution",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16106",
          "name" : "16106",
          "refsource" : "BID",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0002",
          "name" : "ADV-2006-0002",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Direct static code injection vulnerability in phpBook 1.3.2 and earlier allows remote attackers to execute arbitrary PHP code via the e-mail field (mail variable) in a new message, which is written to a PHP file."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:gnu:phpbook:1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:gnu:phpbook:1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:gnu:phpbook:1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:gnu:phpbook:1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:gnu:phpbook:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.3.2"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-04T01:03Z",
    "lastModifiedDate" : "2018-10-19T15:42Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0076",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oaboard",
            "product" : {
              "product_data" : [ {
                "product_name" : "oaboard",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://evuln.com/vulns/3/summary.html",
          "name" : "http://evuln.com/vulns/3/summary.html",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://securitytracker.com/id?1016211",
          "name" : "1016211",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/420676/100/0/threaded",
          "name" : "20060101 [eVuln] oaBoard PHP Code Execution",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/435371/100/0/threaded",
          "name" : "20060530 OaBoard 1.0 Remote File inclusion",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/435859/100/0/threaded",
          "name" : "20060531 Re: OaBoard 1.0 Remote File inclusion",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16105",
          "name" : "16105",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "PHP remote file include vulnerability in forum.php in oaBoard 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the inc parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oaboard:oaboard:1.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-04T01:03Z",
    "lastModifiedDate" : "2018-10-19T15:42Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0077",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "richard_dawe",
            "product" : {
              "product_data" : [ {
                "product_name" : "file_extattr",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18253",
          "name" : "18253",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://sourceforge.net/project/shownotes.php?release_id=382199&group_id=153116",
          "name" : "http://sourceforge.net/project/shownotes.php?release_id=382199&group_id=153116",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.osvdb.org/22160",
          "name" : "22160",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16118",
          "name" : "16118",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0013",
          "name" : "ADV-2006-0013",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Off-by-one error in the getfattr function in File::ExtAttr before 0.03 allows attackers to trigger a buffer overflow via unspecified attack vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:richard_dawe:file_extattr:0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:richard_dawe:file_extattr:0.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 2.1
        },
        "severity" : "LOW",
        "exploitabilityScore" : 3.9,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-04T01:03Z",
    "lastModifiedDate" : "2011-03-08T02:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0078",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "haddad_said",
            "product" : {
              "product_data" : [ {
                "product_name" : "b-net_software",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://evuln.com/vulns/10/summary.html",
          "name" : "http://evuln.com/vulns/10/summary.html",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18271",
          "name" : "18271",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/316",
          "name" : "316",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://sourceforge.net/project/shownotes.php?release_id=442067&group_id=117067",
          "name" : "http://sourceforge.net/project/shownotes.php?release_id=442067&group_id=117067",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/22190",
          "name" : "22190",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/22191",
          "name" : "22191",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/420673/100/0/threaded",
          "name" : "20060102 [eVuln] B-net Software Multiple XSS Vulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/444320/100/0/threaded",
          "name" : "20060825 Re: [eVuln] B-net Software Multiple XSS Vulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16114",
          "name" : "16114",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0018",
          "name" : "ADV-2006-0018",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple cross-site scripting (XSS) vulnerabilities in B-net Software 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) name and (2) shout variables to (a) shout.php, or the (3) title and (4) message variables to (b) guestbook.php."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:haddad_said:b-net_software:1.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-04T06:03Z",
    "lastModifiedDate" : "2018-10-19T15:42Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0079",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "scoznet",
            "product" : {
              "product_data" : [ {
                "product_name" : "scozbook",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.1_beta",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://evuln.com/vulns/11/summary.html",
          "name" : "http://evuln.com/vulns/11/summary.html",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/8476",
          "name" : "8476",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/318",
          "name" : "318",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/22221",
          "name" : "22221",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/420675/100/0/threaded",
          "name" : "20060102 [eVuln] ScozBook \"adminname\" Authentication Bypass",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16115",
          "name" : "16115",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0027",
          "name" : "ADV-2006-0027",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in auth.php in ScozNet ScozBook BETA 1.1 allows remote attackers to execute arbitrary SQL commands via the username field (adminname variable)."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:scoznet:scozbook:1.1_beta:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-04T06:03Z",
    "lastModifiedDate" : "2018-10-19T15:42Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0080",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "jelsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "vbulletin",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.5.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://kapda.ir/advisory-177.html",
          "name" : "http://kapda.ir/advisory-177.html",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18299",
          "name" : "18299",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/22210",
          "name" : "22210",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/22220",
          "name" : "22220",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/420663/100/0/threaded",
          "name" : "20060101 [KAPDA::#19] - Html Injection in vBulletin 3.5.2",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/421310/100/0/threaded",
          "name" : "20060108 Html_Injection in vBulletin 3.5.2",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16116",
          "name" : "16116",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0033",
          "name" : "ADV-2006-0033",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in vBulletin 3.5.2, and possibly earlier versions, allows remote attackers to inject arbitrary web script or HTML via the title of an event, which is not properly filtered by (1) calendar.php and (2) reminder.php."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:jelsoft:vbulletin:3.5.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-04T06:03Z",
    "lastModifiedDate" : "2018-10-19T15:42Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0081",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "intel",
            "product" : {
              "product_data" : [ {
                "product_name" : "graphics_accelerator_driver",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.14.10.4308",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-399"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://seclists.org/fulldisclosure/2006/Jan/32",
          "name" : "20060103 Re: Buffer Overflow vulnerability in Windows Display Manager [Suspected]",
          "refsource" : "FULLDISC",
          "tags" : [ ]
        }, {
          "url" : "http://seclists.org/fulldisclosure/2006/Jan/8",
          "name" : "20060102 Buffer Overflow vulnerability in Windows Display Manager [Suspected]",
          "refsource" : "FULLDISC",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18286",
          "name" : "18286",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/22196",
          "name" : "22196",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16127",
          "name" : "16127",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0017",
          "name" : "ADV-2006-0017",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "ialmnt5.sys in the ialmrnt5 display driver in Intel Graphics Accelerator Driver 6.14.10.4308 allows attackers to cause a denial of service (crash or screen resolution change) via a long text field, as demonstrated using a long window title."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:intel:graphics_accelerator_driver:6.14.10.4308:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.8
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-04T06:03Z",
    "lastModifiedDate" : "2016-12-20T02:59Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0082",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "imagemagick",
            "product" : {
              "product_data" : [ {
                "product_name" : "imagemagick",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.2.3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-134"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "ftp://patches.sgi.com/support/free/security/advisories/20060301-01.U.asc",
          "name" : "20060301-01-U",
          "refsource" : "SGI",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=345876",
          "name" : "http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=345876",
          "refsource" : "CONFIRM",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2006-0178.html",
          "name" : "RHSA-2006:0178",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18261",
          "name" : "18261",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18607",
          "name" : "18607",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18851",
          "name" : "18851",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18871",
          "name" : "18871",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/19030",
          "name" : "19030",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/19183",
          "name" : "19183",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/19408",
          "name" : "19408",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/22998",
          "name" : "22998",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/23090",
          "name" : "23090",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/28800",
          "name" : "28800",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/500",
          "name" : "500",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1015623",
          "name" : "1015623",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://slackware.com/security/viewer.php?l=slackware-security&y=2006&m=slackware-security.341682",
          "name" : "SSA:2006-045-03",
          "refsource" : "SLACKWARE",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://sunsolve.sun.com/search/document.do?assetkey=1-26-231321-1",
          "name" : "231321",
          "refsource" : "SUNALERT",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2006/dsa-1213",
          "name" : "DSA-1213",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.gentoo.org/security/en/glsa/glsa-200602-06.xml",
          "name" : "GLSA-200602-06",
          "refsource" : "GENTOO",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.gentoo.org/security/en/glsa/glsa-200602-13.xml",
          "name" : "GLSA-200602-13.xml",
          "refsource" : "GENTOO",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDKSA-2006:024",
          "name" : "MDKSA-2006:024",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.novell.com/linux/security/advisories/2006_06_sr.html",
          "name" : "SUSE-SR:2006:006",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/452718/100/100/threaded",
          "name" : "20061127 rPSA-2006-0218-1 ImageMagick",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/12717",
          "name" : "12717",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.ubuntu.com/usn/usn-246-1",
          "name" : "USN-246-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0412",
          "name" : "ADV-2008-0412",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://issues.rpath.com/browse/RPL-389",
          "name" : "https://issues.rpath.com/browse/RPL-389",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10717",
          "name" : "oval:org.mitre.oval:def:10717",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Format string vulnerability in the SetImageInfo function in image.c for ImageMagick 6.2.3 and other versions, and GraphicsMagick, allows user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via a numeric format string specifier such as %d in the file name, a variant of CVE-2005-0397, and as demonstrated using the convert program."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:imagemagick:imagemagick:6.2.3:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:H/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "HIGH",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.1
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 4.9,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2006-01-04T23:03Z",
    "lastModifiedDate" : "2018-10-19T15:42Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0083",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "stefan_frings",
            "product" : {
              "product_data" : [ {
                "product_name" : "sms_server_tools",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18343",
          "name" : "18343",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18357",
          "name" : "18357",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.debian.org/security/2005/dsa-930",
          "name" : "DSA-930",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/22287",
          "name" : "22287",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16188",
          "name" : "16188",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24034",
          "name" : "smstools-logging-format-string(24034)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Format string vulnerability in the logging code of SMS Server Tools (smstools) 1.14.8 and earlier allows local users to execute arbitrary code via unspecified attack vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:stefan_frings:sms_server_tools:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 4.6
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 3.9,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-09T20:03Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0084",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "rasmp",
            "product" : {
              "product_data" : [ {
                "product_name" : "rasmp",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://attrition.org/pipermail/vim/2006-January/000486.html",
          "name" : "20060116 vendor ack/fix: 22198: raSMP index.php User-Agent Field XSS (fwd)",
          "refsource" : "VIM",
          "tags" : [ ]
        }, {
          "url" : "http://evuln.com/vulns/13/summary.html",
          "name" : "http://evuln.com/vulns/13/summary.html",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18292",
          "name" : "18292",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1015432",
          "name" : "1015432",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/22198",
          "name" : "22198",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16138",
          "name" : "16138",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0030",
          "name" : "ADV-2006-0030",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting vulnerability in index.php in raSMP 2.0.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the $_SERVER[HTTP_USER_AGENT] variable (User-Agent header)."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rasmp:rasmp:2.0.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-05T11:03Z",
    "lastModifiedDate" : "2011-03-08T02:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0085",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "nkads",
            "product" : {
              "product_data" : [ {
                "product_name" : "nkads",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0alfa2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0alfa3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18302",
          "name" : "18302",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/22206",
          "name" : "22206",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.soulblack.com.ar/repo/papers/advisory/nkads_advisory.txt",
          "name" : "http://www.soulblack.com.ar/repo/papers/advisory/nkads_advisory.txt",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0040",
          "name" : "ADV-2006-0040",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in Nkads 1.0 alfa 3 allows remote attackers to execute arbitrary SQL commands via the (1) usuario_nkads_admin or (2) password_nkads_admin parameters."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:nkads:nkads:1.0alfa2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:nkads:nkads:1.0alfa3:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-05T11:03Z",
    "lastModifiedDate" : "2011-03-08T02:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0086",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "next_generation_image_gallery",
            "product" : {
              "product_data" : [ {
                "product_name" : "next_generation_image_gallery",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.0.1_lite",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/ref/22/22202-nextgen.txt",
          "name" : "http://osvdb.org/ref/22/22202-nextgen.txt",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18309",
          "name" : "18309",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/22202",
          "name" : "22202",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0037",
          "name" : "ADV-2006-0037",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting vulnerability in index.php in Next Generation Image Gallery 0.0.1 Lite Edition allows remote attackers to inject arbitrary web script or HTML via the page parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:next_generation_image_gallery:next_generation_image_gallery:0.0.1_lite:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-05T11:03Z",
    "lastModifiedDate" : "2011-03-08T02:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0087",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "lizard_cart",
            "product" : {
              "product_data" : [ {
                "product_name" : "lizard_cart_cms",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0.4",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18297",
          "name" : "18297",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/314",
          "name" : "314",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1015435",
          "name" : "1015435",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.evuln.com/vulns/12/summary.html",
          "name" : "http://www.evuln.com/vulns/12/summary.html",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/22199",
          "name" : "22199",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/22200",
          "name" : "22200",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/420772/100/0/threaded",
          "name" : "20060104 [eVuln] Lizard Cart CMS SQL Injection Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16140",
          "name" : "16140",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0029",
          "name" : "ADV-2006-0029",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in (1) pages.php and (2) detail.php in Lizard Cart CMS 1.04 allows remote attackers to execute arbitrary SQL commands via the id parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:lizard_cart:lizard_cart_cms:1.0.4:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-05T11:03Z",
    "lastModifiedDate" : "2018-10-19T15:42Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0088",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "intouch",
            "product" : {
              "product_data" : [ {
                "product_name" : "intouch",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.5.1_alpha",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://evuln.com/vulns/8/summary.html",
          "name" : "http://evuln.com/vulns/8/summary.html",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/22382",
          "name" : "22382",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/420672/100/0/threaded",
          "name" : "20060101 [eVuln] inTouch Authentication Bypass",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16110",
          "name" : "16110",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0026",
          "name" : "ADV-2006-0026",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/23954",
          "name" : "intouch-intouch-sql-injection(23954)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in intouch.lib.php in inTouch 0.5.1 Alpha allows remote attackers to execute arbitrary SQL commands via the user parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:intouch:intouch:0.5.1_alpha:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-05T11:03Z",
    "lastModifiedDate" : "2018-10-19T15:42Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0089",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "esri",
            "product" : {
              "product_data" : [ {
                "product_name" : "arcpad",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.0.0.156",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18294",
          "name" : "18294",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://users.pandora.be/bratax/advisories/b007.html",
          "name" : "http://users.pandora.be/bratax/advisories/b007.html",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/22208",
          "name" : "22208",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16136",
          "name" : "16136",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0032",
          "name" : "ADV-2006-0032",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Buffer overflow in ESRI ArcPad 7.0.0.156 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a .amp file with a COORDSYS tag with a long string attribute."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:esri:arcpad:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "7.0.0.156"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-05T11:03Z",
    "lastModifiedDate" : "2011-03-08T02:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0090",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "idv_directory_viewer",
            "product" : {
              "product_data" : [ {
                "product_name" : "idv_directory_viewer",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2005.1_b1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18298",
          "name" : "18298",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://sourceforge.net/project/shownotes.php?release_id=382593&group_id=152499",
          "name" : "http://sourceforge.net/project/shownotes.php?release_id=382593&group_id=152499",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16137",
          "name" : "16137",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0031",
          "name" : "ADV-2006-0031",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Directory traversal vulnerability in index.php in IDV Directory Viewer before 2005.1 allows remote attackers to view arbitrary directory contents via a .. (dot dot) in the dir parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:idv_directory_viewer:idv_directory_viewer:2005.1_b1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-05T11:03Z",
    "lastModifiedDate" : "2011-03-08T02:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0091",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "open-xchange",
            "product" : {
              "product_data" : [ {
                "product_name" : "open-xchange",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.8.1.6",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://marc.info/?l=full-disclosure&m=113629092325679&w=2",
          "name" : "20060103 Open Xchange XSS",
          "refsource" : "FULLDISC",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18285",
          "name" : "18285",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1015431",
          "name" : "1015431",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0034",
          "name" : "ADV-2006-0034",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in webmail in Open-Xchange 0.8.1-6 and earlier, with \"Inline HTML\" enabled, allows remote attackers to inject arbitrary web script or HTML via e-mail attachments, which are rendered inline."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:open-xchange:open-xchange:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "0.8.1.6"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-05T11:03Z",
    "lastModifiedDate" : "2016-10-18T03:38Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0092",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ ]
        } ]
      },
      "references" : {
        "reference_data" : [ ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2006-0992, CVE-2006-0158.  Reason: this candidate was intended for one issue, but a typo caused it to be associated with a Novell/Groupwise issue.  In addition, this issue was a duplicate of a SiteSuite issue that was also assigned CVE-2006-0158.  Notes: All CVE users should consult CVE-2006-0992 and CVE-2006-0158 to determine which ID is appropriate.  All references and descriptions in this candidate have been removed to prevent accidental usage."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ ]
    },
    "impact" : { },
    "publishedDate" : "2006-01-05T11:03Z",
    "lastModifiedDate" : "2008-09-10T19:55Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0093",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ecardmax.com",
            "product" : {
              "product_data" : [ {
                "product_name" : "atcard_me_php",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/ref/22/22203-ecardmax.txt",
          "name" : "http://osvdb.org/ref/22/22203-ecardmax.txt",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://secunia.com/advisories/18306",
          "name" : "18306",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/22203",
          "name" : "22203",
          "refsource" : "OSVDB",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0039",
          "name" : "ADV-2006-0039",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in index.php in @Card ME PHP allows remote attackers to inject arbitrary web script or HTML via the cat parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ecardmax.com:atcard_me_php:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-05T11:03Z",
    "lastModifiedDate" : "2011-03-08T02:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0094",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oaboard",
            "product" : {
              "product_data" : [ {
                "product_name" : "oaboard",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-94"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/17373",
          "name" : "17373",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0028",
          "name" : "ADV-2006-0028",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "PHP remote file include vulnerability in forum.php in oaBoard 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the inc_stat parameter, a different vulnerability than CVE-2006-0076. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oaboard:oaboard:1.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-05T11:03Z",
    "lastModifiedDate" : "2011-08-23T04:00Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0095",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "linux",
            "product" : {
              "product_data" : [ {
                "product_name" : "linux_kernel",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.8.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.12.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.12.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.12.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.12.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.14.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.14.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.14.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.14.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.15",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://marc.info/?l=linux-kernel&m=113640535312572&w=2",
          "name" : "[linux-kernel] 20060104 [Patch 2.6] dm-crypt: zero key before freeing it",
          "refsource" : "MLIST",
          "tags" : [ ]
        }, {
          "url" : "http://marc.info/?l=linux-kernel&m=113641114812886&w=2",
          "name" : "[linux-kernel] 20060104 [Patch 2.6] dm-crypt: Zero key material before free to avoid information leak",
          "refsource" : "MLIST",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18487",
          "name" : "18487",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18527",
          "name" : "18527",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18774",
          "name" : "18774",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/19160",
          "name" : "19160",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/19374",
          "name" : "19374",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/20398",
          "name" : "20398",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/388",
          "name" : "388",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1015740",
          "name" : "1015740",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2006/dsa-1017",
          "name" : "DSA-1017",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDKSA-2006:040",
          "name" : "MDKSA-2006:040",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.novell.com/linux/security/advisories/2006-05-31.html",
          "name" : "SUSE-SA:2006:028",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/22418",
          "name" : "22418",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/archives/fedora-announce-list/2006-February/msg00037.html",
          "name" : "FEDORA-2006-102",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2006-0132.html",
          "name" : "RHSA-2006:0132",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/427981/100/0/threaded",
          "name" : "FLSA:157459-4",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16301",
          "name" : "16301",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.trustix.org/errata/2006/0004",
          "name" : "2006-0004",
          "refsource" : "TRUSTIX",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0235",
          "name" : "ADV-2006-0235",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24189",
          "name" : "kernel-dmcrypt-information-disclosure(24189)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11192",
          "name" : "oval:org.mitre.oval:def:11192",
          "refsource" : "OVAL",
          "tags" : [ ]
        }, {
          "url" : "https://usn.ubuntu.com/244-1/",
          "name" : "USN-244-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "dm-crypt in Linux kernel 2.6.15 and earlier does not clear a structure before it is freed, which leads to a memory disclosure that could allow local users to obtain sensitive information about a cryptographic key."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.8.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.9:2.6.20:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11.12:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.12:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.12.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.12.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.12.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.12.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.13:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.14:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.14:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.14:rc2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.14:rc3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.14:rc4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.14.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.14.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.14.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.14.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.15:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.15:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.15:rc3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.15:rc4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.15:rc5:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.15:rc6:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.15:rc7:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 2.1
        },
        "severity" : "LOW",
        "exploitabilityScore" : 3.9,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-06T11:03Z",
    "lastModifiedDate" : "2018-10-19T15:42Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0096",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "linux",
            "product" : {
              "product_data" : [ {
                "product_name" : "linux_kernel",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.4.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.4.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.4.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.4.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.4.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.4.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.4.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.4.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.4.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.4.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.4.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.4.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.4.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.4.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.4.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.4.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.4.16",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.4.17",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.4.18",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.4.19",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.4.20",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.4.21",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.4.22",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.4.23",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.4.23_ow2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.4.24",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.4.24_ow1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.4.25",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.4.26",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.4.27",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.4.28",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.8.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.12.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.12.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.12.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.12.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.14.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.14.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.14.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.14.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.15",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://linux.bkbits.net:8080/linux-2.4/cset@1.1448.91.23?nav=index.html|src/|src/drivers|src/drivers/net|src/drivers/net/wan|related/drivers/net/wan/sdla.c",
          "name" : "http://linux.bkbits.net:8080/linux-2.4/cset@1.1448.91.23?nav=index.html|src/|src/drivers|src/drivers/net|src/drivers/net/wan|related/drivers/net/wan/sdla.c",
          "refsource" : "CONFIRM",
          "tags" : [ "Broken Link" ]
        }, {
          "url" : "http://secunia.com/advisories/18527",
          "name" : "18527",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18977",
          "name" : "18977",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/19374",
          "name" : "19374",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.debian.org/security/2006/dsa-1017",
          "name" : "DSA-1017",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.kernel.org/git/?p=linux/kernel/git/tglx/history.git;a=commitdiff;h=0f1d4813a4a65296e1131f320a60741732bc068f",
          "name" : "http://www.kernel.org/git/?p=linux/kernel/git/tglx/history.git;a=commitdiff;h=0f1d4813a4a65296e1131f320a60741732bc068f",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16304",
          "name" : "16304",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://wwwnew.mandriva.com/security/advisories?name=MDKSA-2006:044",
          "name" : "MDKSA-2006:044",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "https://usn.ubuntu.com/244-1/",
          "name" : "USN-244-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "wan/sdla.c in Linux kernel 2.6.x before 2.6.11 and 2.4.x before 2.4.29 does not require the CAP_SYS_RAWIO privilege for an SDLA firmware upgrade, with unknown impact and local attack vectors.  NOTE: further investigation suggests that this issue requires root privileges to exploit, since it is protected by CAP_NET_ADMIN; thus it might not be a vulnerability, although capabilities provide finer distinctions between privilege levels."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.4.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.4.0:test1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.4.0:test10:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.4.0:test11:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.4.0:test12:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.4.0:test2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.4.0:test3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.4.0:test4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.4.0:test5:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.4.0:test6:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.4.0:test7:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.4.0:test8:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.4.0:test9:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.4.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.4.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.4.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.4.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.4.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.4.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.4.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.4.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.4.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.4.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.4.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.4.12:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.4.13:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.4.14:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.4.15:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.4.16:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.4.17:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.4.18:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.4.18:*:x86:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.4.18:pre1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.4.18:pre2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.4.18:pre3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.4.18:pre4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.4.18:pre5:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.4.18:pre6:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.4.18:pre7:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.4.18:pre8:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.4.19:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.4.19:pre1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.4.19:pre2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.4.19:pre3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.4.19:pre4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.4.19:pre5:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.4.19:pre6:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.4.20:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.4.21:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.4.21:pre1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.4.21:pre4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.4.21:pre7:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.4.22:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.4.23:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.4.23:pre9:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.4.23_ow2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.4.24:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.4.24_ow1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.4.25:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.4.26:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.4.27:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.4.27:pre1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.4.27:pre2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.4.27:pre3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.4.27:pre4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.4.27:pre5:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.4.28:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.8.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.9:2.6.20:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11.12:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.12:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.12.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.12.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.12.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.12.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.13:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.14:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.14:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.14:rc2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.14:rc3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.14:rc4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.14.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.14.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.14.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.14.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.15:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.15:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.15:rc3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.15:rc4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.15:rc5:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.15:rc6:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.15:rc7:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.2
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 3.9,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-06T11:03Z",
    "lastModifiedDate" : "2018-10-03T21:34Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0097",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "php",
            "product" : {
              "product_data" : [ {
                "product_name" : "php",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.3.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.4.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.4.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.4.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://archives.neohapsis.com/archives/fulldisclosure/2006-01/0274.html",
          "name" : "20060108 RE: Windows PHP 4.x \"0-day\" buffer overflow",
          "refsource" : "FULLDISC",
          "tags" : [ ]
        }, {
          "url" : "http://lists.grok.org.uk/pipermail/full-disclosure/2006-January/041013.html",
          "name" : "20060105 Windows PHP 4.x \"0-day\" buffer overflow",
          "refsource" : "FULLDISC",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18275",
          "name" : "18275",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/22232",
          "name" : "22232",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.php.net/ChangeLog-4.php#4.4.3",
          "name" : "http://www.php.net/ChangeLog-4.php#4.4.3",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/420986/100/0/threaded",
          "name" : "20060105 Windows PHP 4.x \"0-day\" buffer overflow",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16145",
          "name" : "16145",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0046",
          "name" : "ADV-2006-0046",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Stack-based buffer overflow in the create_named_pipe function in libmysql.c in PHP 4.3.10 and 4.4.x before 4.4.3 for Windows allows attackers to execute arbitrary code via a long (1) arg_host or (2) arg_unix_socket argument, as demonstrated by a long named pipe variable in the host argument to the mysql_connect function."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.3.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.4.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.4.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.4.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-06T11:03Z",
    "lastModifiedDate" : "2018-10-19T15:42Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0098",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "openbsd",
            "product" : {
              "product_data" : [ {
                "product_name" : "openbsd",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.8",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.7/common/008_fd.patch",
          "name" : "ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.7/common/008_fd.patch",
          "refsource" : "MISC",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://secunia.com/advisories/18296",
          "name" : "18296",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1015437",
          "name" : "1015437",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.openbsd.org/errata37.html#fd",
          "name" : "[3.7] 20060105 008: SECURITY FIX: January 5, 2006",
          "refsource" : "OPENBSD",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.osvdb.org/22231",
          "name" : "22231",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16144",
          "name" : "16144",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The dupfdopen function in sys/kern/kern_descrip.c in OpenBSD 3.7 and 3.8 allows local users to re-open arbitrary files by using setuid programs to access file descriptors using /dev/fd/."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:openbsd:openbsd:3.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:openbsd:openbsd:3.8:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 4.6
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 3.9,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-06T11:03Z",
    "lastModifiedDate" : "2008-09-05T20:58Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0099",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "valdersoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "valdersoft_shopping_cart",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://downloads.securityfocus.com/vulnerabilities/exploits/cijfer-vscxpl.pl",
          "name" : "http://downloads.securityfocus.com/vulnerabilities/exploits/cijfer-vscxpl.pl",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16126",
          "name" : "16126",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/1401",
          "name" : "1401",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "PHP remote file include vulnerability in (1) include/templates/categories/default.php and (2) certain other include/templates/categories/ PHP scripts in Valdersoft Shopping Cart 3.0 allows remote attackers to execute arbitrary code via a URL in the catalogDocumentRoot parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:valdersoft:valdersoft_shopping_cart:3.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-06T11:03Z",
    "lastModifiedDate" : "2017-10-19T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0100",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "nicosw",
            "product" : {
              "product_data" : [ {
                "product_name" : "nicoftp",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.0.1.19",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://securityreason.com/securityalert/317",
          "name" : "317",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/420670/100/0/threaded",
          "name" : "20060102 NicoFTP Stack Overflow",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Buffer overflow in NicoFTP 3.0.1.19 and earlier might allow local users to execute arbitrary code via a long string in the \"Name of site\" field of an FTP account.  NOTE: because this program executes with the privileges of the invoking user, and because remote programs do not normally have the ability to create or modify FTP accounts in this program, there may not be a typical attack vector for the issue that crosses privilege boundaries.  Therefore this may not be a vulnerability."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:nicosw:nicoftp:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "3.0.1.19"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 4.6
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 3.9,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-06T11:03Z",
    "lastModifiedDate" : "2018-10-19T15:42Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0101",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "sblog",
            "product" : {
              "product_data" : [ {
                "product_name" : "sblog",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.7.1_build2005-12-02_beta",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/ref/22/22373-sblog.txt",
          "name" : "http://osvdb.org/ref/22/22373-sblog.txt",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/22373",
          "name" : "22373",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/22374",
          "name" : "22374",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0041",
          "name" : "ADV-2006-0041",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/23979",
          "name" : "sblog-multiple-scripts-xss(23979)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple cross-site scripting (XSS) vulnerabilities in sBLOG 0.7.1 Beta 20051202 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) p and (2) keyword parameters in (a) index.php and (b) search.php."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sblog:sblog:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "0.7.1_build2005-12-02_beta"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-06T11:03Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0102",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ralph_capper",
            "product" : {
              "product_data" : [ {
                "product_name" : "tinyphpforum",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.46",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.47",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.48",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.49",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.499",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://evuln.com/vulns/14/summary.html",
          "name" : "http://evuln.com/vulns/14/summary.html",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18293",
          "name" : "18293",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/320",
          "name" : "320",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1015436",
          "name" : "1015436",
          "refsource" : "SECTRACK",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.osvdb.org/22256",
          "name" : "22256",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/420933/100/0/threaded",
          "name" : "20060105 [eVuln] TinyPHPForum Multiple Vulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0054",
          "name" : "ADV-2006-0054",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in TinyPHPForum (TPF) 3.6 and earlier allows remote attackers to inject arbitrary web script via a javascript: scheme in an \"[a]\" bbcode tag, possibly the txt parameter to action.php."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ralph_capper:tinyphpforum:3.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ralph_capper:tinyphpforum:3.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ralph_capper:tinyphpforum:3.46:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ralph_capper:tinyphpforum:3.47:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ralph_capper:tinyphpforum:3.48:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ralph_capper:tinyphpforum:3.49:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ralph_capper:tinyphpforum:3.499:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-06T11:03Z",
    "lastModifiedDate" : "2018-10-19T15:42Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0103",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ralph_capper",
            "product" : {
              "product_data" : [ {
                "product_name" : "tinyphpforum",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.46",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.47",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.48",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.49",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.499",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-200"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://evuln.com/vulns/14/summary.html",
          "name" : "http://evuln.com/vulns/14/summary.html",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18293",
          "name" : "18293",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/320",
          "name" : "320",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1015436",
          "name" : "1015436",
          "refsource" : "SECTRACK",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.osvdb.org/22257",
          "name" : "22257",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/420933/100/0/threaded",
          "name" : "20060105 [eVuln] TinyPHPForum Multiple Vulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/431133/100/0/threaded",
          "name" : "20060417 Tiny PHP forum - vulns",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0054",
          "name" : "ADV-2006-0054",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24016",
          "name" : "tinyphpforum-users-information-disclosure(24016)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "TinyPHPForum 3.6 and earlier stores the (1) users/[USERNAME].hash and (2) users/[USERNAME].email files under the web root with insufficient access control, which allows remote attackers to list all registered users and possibly obtain other sensitive information."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ralph_capper:tinyphpforum:3.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ralph_capper:tinyphpforum:3.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ralph_capper:tinyphpforum:3.46:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ralph_capper:tinyphpforum:3.47:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ralph_capper:tinyphpforum:3.48:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ralph_capper:tinyphpforum:3.49:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ralph_capper:tinyphpforum:3.499:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-06T11:03Z",
    "lastModifiedDate" : "2018-10-19T15:42Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0104",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ralph_capper",
            "product" : {
              "product_data" : [ {
                "product_name" : "tinyphpforum",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.46",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.47",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.48",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.49",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.499",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://evuln.com/vulns/14/exploit.html",
          "name" : "http://evuln.com/vulns/14/exploit.html",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://evuln.com/vulns/14/summary.html",
          "name" : "http://evuln.com/vulns/14/summary.html",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18293",
          "name" : "18293",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/320",
          "name" : "320",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1015436",
          "name" : "1015436",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/22258",
          "name" : "22258",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/420933/100/0/threaded",
          "name" : "20060105 [eVuln] TinyPHPForum Multiple Vulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16163",
          "name" : "16163",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0054",
          "name" : "ADV-2006-0054",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Directory traversal vulnerability in TinyPHPForum 3.6 and earlier allows remote attackers to create a new user account, create a new topic, or view the profile of a user account, as demonstrated via a .. (dot dot) in the uname parameter to profile.php."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ralph_capper:tinyphpforum:3.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ralph_capper:tinyphpforum:3.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ralph_capper:tinyphpforum:3.46:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ralph_capper:tinyphpforum:3.47:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ralph_capper:tinyphpforum:3.48:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ralph_capper:tinyphpforum:3.49:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ralph_capper:tinyphpforum:3.499:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-06T11:03Z",
    "lastModifiedDate" : "2018-10-19T15:42Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0105",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "postgresql",
            "product" : {
              "product_data" : [ {
                "product_name" : "postgresql",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.1.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://archives.postgresql.org/pgsql-announce/2006-01/msg00001.php",
          "name" : "[pgsql-announce] 20060109 CRITICAL RELEASE: Minor Releases to Fix DoS Vulnerability",
          "refsource" : "MLIST",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://secunia.com/advisories/18419",
          "name" : "18419",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/327",
          "name" : "327",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1015482",
          "name" : "1015482",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.postgresql.org/about/news.456",
          "name" : "http://www.postgresql.org/about/news.456",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/421592/100/0/threaded",
          "name" : "20060111 PostgreSQL security releases 8.0.6 and 8.1.2",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16201",
          "name" : "16201",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0114",
          "name" : "ADV-2006-0114",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24049",
          "name" : "postgresql-connection-request-dos(24049)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "PostgreSQL 8.0.x before 8.0.6 and 8.1.x before 8.1.2, when running on Windows, allows remote attackers to cause a denial of service (postmaster exit and no new connections) via a large number of simultaneous connection requests."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:8.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:8.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:8.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:8.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:8.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:8.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:8.1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:8.1.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-10T20:03Z",
    "lastModifiedDate" : "2018-10-19T15:42Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0106",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "wine",
            "product" : {
              "product_data" : [ {
                "product_name" : "wine",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.9.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.9.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.9.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2005-09-30",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=346197",
          "name" : "http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=346197",
          "refsource" : "MISC",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://lists.immunitysec.com/pipermail/dailydave/2006-January/002806.html",
          "name" : "[Dailydave] 20060105 WMF goes away :<",
          "refsource" : "MLIST",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18323",
          "name" : "18323",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18451",
          "name" : "18451",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18549",
          "name" : "18549",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18578",
          "name" : "18578",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2006/dsa-954",
          "name" : "DSA-954",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.gentoo.org/security/en/glsa/glsa-200601-09.xml",
          "name" : "GLSA-200601-09",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDKSA-2006:014",
          "name" : "MDKSA-2006:014",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.novell.com/linux/security/advisories/2006_02_sr.html",
          "name" : "SUSE-SR:2006:002",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/422128/100/0/threaded",
          "name" : "20060117 ERRATA: [ GLSA 200601-09 ] Wine: Windows Metafile SETABORTPROC vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0098",
          "name" : "ADV-2006-0098",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/23846",
          "name" : "win-wmf-execute-code(23846)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "gdi/driver.c and gdi/printdrv.c in Wine 20050930, and other versions, implement the SETABORTPROC GDI Escape function call for Windows Metafile (WMF) files, which allows attackers to execute arbitrary code, the same vulnerability as CVE-2005-4560 but in a different codebase."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wine:wine:0.9.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wine:wine:0.9.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wine:wine:0.9.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wine:wine:2005-09-30:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-06T18:03Z",
    "lastModifiedDate" : "2018-10-19T15:42Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0107",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "idea_development_id_oy",
            "product" : {
              "product_data" : [ {
                "product_name" : "timecan_cms",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18324",
          "name" : "18324",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/22252",
          "name" : "22252",
          "refsource" : "OSVDB",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16159",
          "name" : "16159",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24014",
          "name" : "timecancms-sql-injection(24014)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in Timecan CMS allows remote attackers to execute arbitrary SQL commands via the viewID parameter.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.  Due to the unavailability of the original source, it cannot be determined if this is the same issue as identified by CVE-2006-0108."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:idea_development_id_oy:timecan_cms:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-07T00:03Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0108",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "idea_development_id_oy",
            "product" : {
              "product_data" : [ {
                "product_name" : "timecan_cms",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.osvdb.org/22252",
          "name" : "22252",
          "refsource" : "OSVDB",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.osvdb.org/22253",
          "name" : "22253",
          "refsource" : "OSVDB",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0078",
          "name" : "ADV-2006-0078",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24014",
          "name" : "timecancms-sql-injection(24014)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in mcl_login.asp in Timecan CMS allows remote attackers to execute arbitrary SQL commands via the email parameter.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.  Due to the unavailability of the original source, it cannot be determined if this is the same issue as identified by CVE-2006-0107."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:idea_development_id_oy:timecan_cms:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-07T00:03Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0109",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "modular_merchant",
            "product" : {
              "product_data" : [ {
                "product_name" : "shopping_cart",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://attrition.org/pipermail/vim/2006-February/000548.html",
          "name" : "20060214 vendor ack/fix 22243: Modular Merchant Marketplace Shopping Cart category.php cat Variable XSS (fwd)",
          "refsource" : "VIM",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/ref/22/22243-modular.txt",
          "name" : "http://osvdb.org/ref/22/22243-modular.txt",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18320",
          "name" : "18320",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.modularmerchant.com/forums/viewtopic.php?t=46",
          "name" : "http://www.modularmerchant.com/forums/viewtopic.php?t=46",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/22243",
          "name" : "22243",
          "refsource" : "OSVDB",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16160",
          "name" : "16160",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0076",
          "name" : "ADV-2006-0076",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting vulnerability in category.php in Modular Merchant Shopping Cart allows remote attackers to inject arbitrary web script or HTML via the cat parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:modular_merchant:shopping_cart:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-07T00:03Z",
    "lastModifiedDate" : "2011-03-08T02:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0110",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "javier_suarez_sanz",
            "product" : {
              "product_data" : [ {
                "product_name" : "foro_domus",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.10",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://evuln.com/vulns/16/summary.html",
          "name" : "http://evuln.com/vulns/16/summary.html",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://secunia.com/advisories/18327",
          "name" : "18327",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/22263",
          "name" : "22263",
          "refsource" : "OSVDB",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/421056/100/0/threaded",
          "name" : "20060106 [eVuln] Proyecto Domus 'email' XSS Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16154",
          "name" : "16154",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0073",
          "name" : "ADV-2006-0073",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24020",
          "name" : "domus-escribir-xss(24020)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in escribir.php in Foro Domus 2.10 allows remote attackers to inject arbitrary web script via the email parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:javier_suarez_sanz:foro_domus:2.10:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-07T00:03Z",
    "lastModifiedDate" : "2018-10-19T15:42Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0111",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "boxcar_media",
            "product" : {
              "product_data" : [ {
                "product_name" : "shopping_cart",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/ref/22/22360-boxcar.txt",
          "name" : "http://osvdb.org/ref/22/22360-boxcar.txt",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/22360",
          "name" : "22360",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0080",
          "name" : "ADV-2006-0080",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24019",
          "name" : "boxcar-index-xss(24019)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting vulnerability in index.php in Boxcar Media Shopping Cart allows remote attackers to inject arbitrary web script or HTML via the (1) parent or (2) pg parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:boxcar_media:shopping_cart:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-07T00:03Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0112",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "enhanced_simple_php_gallery",
            "product" : {
              "product_data" : [ {
                "product_name" : "enhanced_simple_php_gallery",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.7",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/ref/22/22201-espg.txt",
          "name" : "http://osvdb.org/ref/22/22201-espg.txt",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://secunia.com/advisories/18310",
          "name" : "18310",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/22201",
          "name" : "22201",
          "refsource" : "OSVDB",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0036",
          "name" : "ADV-2006-0036",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in index.php in Enhanced Simple PHP Gallery 1.7 allows remote attackers to inject arbitrary web script or HTML via the dir parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:enhanced_simple_php_gallery:enhanced_simple_php_gallery:1.7:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-07T01:03Z",
    "lastModifiedDate" : "2011-03-08T02:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0113",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "enhanced_simple_php_gallery",
            "product" : {
              "product_data" : [ {
                "product_name" : "enhanced_simple_php_gallery",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.7",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/ref/22/22201-espg.txt",
          "name" : "http://osvdb.org/ref/22/22201-espg.txt",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://secunia.com/advisories/18310",
          "name" : "18310",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/22417",
          "name" : "22417",
          "refsource" : "OSVDB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Enhanced Simple PHP Gallery 1.7 allows remote attackers to obtain the full path of the application via a direct request to sp_helper_functions.php, which leaks the pathname in an error message."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:enhanced_simple_php_gallery:enhanced_simple_php_gallery:1.7:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-07T01:03Z",
    "lastModifiedDate" : "2008-09-05T20:58Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0114",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "joomla",
            "product" : {
              "product_data" : [ {
                "product_name" : "joomla",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0.5",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-264"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://forge.joomla.org/sf/go/artf2950",
          "name" : "http://forge.joomla.org/sf/go/artf2950",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://forum.joomla.org/index.php/topic,29031.0.html",
          "name" : "http://forum.joomla.org/index.php/topic,29031.0.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18361",
          "name" : "18361",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.listerit.com/content/view/116/84/",
          "name" : "http://www.listerit.com/content/view/116/84/",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16185",
          "name" : "16185",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0097",
          "name" : "ADV-2006-0097",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24042",
          "name" : "joomla-vcard-information-disclosure(24042)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The vCard functions in Joomla! 1.0.5 use predictable sequential IDs for vcards and do not restrict access to them, which allows remote attackers to obtain valid e-mail addresses to conduct spam attacks by modifying the contact_id parameter to index2.php."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:joomla:joomla:1.0.5:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-09T11:03Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0115",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oneplug_solutions",
            "product" : {
              "product_data" : [ {
                "product_name" : "oneplug_cms",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/ref/22/22248-oneplug.txt",
          "name" : "http://osvdb.org/ref/22/22248-oneplug.txt",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://secunia.com/advisories/18325",
          "name" : "18325",
          "refsource" : "SECUNIA",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/22248",
          "name" : "22248",
          "refsource" : "OSVDB",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.osvdb.org/22249",
          "name" : "22249",
          "refsource" : "OSVDB",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.osvdb.org/22250",
          "name" : "22250",
          "refsource" : "OSVDB",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16155",
          "name" : "16155",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0079",
          "name" : "ADV-2006-0079",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple SQL injection vulnerabilities in OnePlug Solutions OnePlug CMS allow remote attackers to execute arbitrary SQL commands via the (1) Press_Release_ID parameter in press/details.asp, (2) Service_ID parameter in services/details.asp, and (3) Product_ID parameter in products/details.asp."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oneplug_solutions:oneplug_cms:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-09T11:03Z",
    "lastModifiedDate" : "2011-09-08T04:00Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0116",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "inetstore",
            "product" : {
              "product_data" : [ {
                "product_name" : "inetstore_online",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/ref/22/22251-inetstore.txt",
          "name" : "http://osvdb.org/ref/22/22251-inetstore.txt",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://secunia.com/advisories/18322",
          "name" : "18322",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.attrition.org/pipermail/vim/2006-January/000515.html",
          "name" : "20060127 vendor confirms versions: iNETstore E Commerce Solution - Cross Site Scripting (fwd)",
          "refsource" : "VIM",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/22251",
          "name" : "22251",
          "refsource" : "OSVDB",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/423137/100/0/threaded",
          "name" : "20060126 Re: [OSVDB Mods] iNETstore E Commerce Solution - Cross Site Scripting",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16156",
          "name" : "16156",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0075",
          "name" : "ADV-2006-0075",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting vulnerability search.inetstore in iNETstore Ebusiness Software 2.0 allows remote attackers to inject arbitrary web script or HTML via the searchterm parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:inetstore:inetstore_online:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-09T11:03Z",
    "lastModifiedDate" : "2018-10-19T15:42Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0117",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "lotus_domino",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.5.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.5.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.5.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.5.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.5.4",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "lotus_domino_enterprise_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.5.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.5.4",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "lotus_notes",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.5.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.5.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.5.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.5.4",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18328",
          "name" : "18328",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16158",
          "name" : "16158",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0081",
          "name" : "ADV-2006-0081",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www-1.ibm.com/support/docview.wss?uid=swg27007054",
          "name" : "http://www-1.ibm.com/support/docview.wss?uid=swg27007054",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www-10.lotus.com/ldd/r5fixlist.nsf/5c087391999d06e7852569280062619d/50c634bfe193efa5852570e4001baace?OpenDocument",
          "name" : "http://www-10.lotus.com/ldd/r5fixlist.nsf/5c087391999d06e7852569280062619d/50c634bfe193efa5852570e4001baace?OpenDocument",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www-10.lotus.com/ldd/r5fixlist.nsf/e7dbb5aee9a94c56852570c90056a95d/21d8fd7989fdf78d852570e4001bae68?OpenDocument",
          "name" : "http://www-10.lotus.com/ldd/r5fixlist.nsf/e7dbb5aee9a94c56852570c90056a95d/21d8fd7989fdf78d852570e4001bae68?OpenDocument",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24205",
          "name" : "lotus-cdtomime-dos(24205)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Buffer overflow in IBM Lotus Notes and Domino Server before 6.5.5 allows attackers to cause a denial of service (router crash or hang) via unspecified vectors involving \"CD to MIME Conversion\"."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:lotus_domino:6.5.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:lotus_domino:6.5.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:lotus_domino:6.5.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:lotus_domino:6.5.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:lotus_domino:6.5.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:lotus_domino:6.5.4:*:fp1:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:lotus_domino:6.5.4:*:fp2:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:lotus_domino_enterprise_server:6.5.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:lotus_domino_enterprise_server:6.5.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:lotus_notes:6.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:lotus_notes:6.5.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:lotus_notes:6.5.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:lotus_notes:6.5.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:lotus_notes:6.5.4:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-09T11:03Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0118",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "lotus_domino",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.5.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.5.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.5.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.5.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.5.4",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "lotus_domino_enterprise_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.5.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.5.4",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "lotus_notes",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.5.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.5.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.5.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.5.4",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18328",
          "name" : "18328",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16158",
          "name" : "16158",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0081",
          "name" : "ADV-2006-0081",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www-1.ibm.com/support/docview.wss?uid=swg27007054",
          "name" : "http://www-1.ibm.com/support/docview.wss?uid=swg27007054",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www-10.lotus.com/ldd/r5fixlist.nsf/5c087391999d06e7852569280062619d/50c634bfe193efa5852570e4001baace?OpenDocument",
          "name" : "http://www-10.lotus.com/ldd/r5fixlist.nsf/5c087391999d06e7852569280062619d/50c634bfe193efa5852570e4001baace?OpenDocument",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www-10.lotus.com/ldd/r5fixlist.nsf/e7dbb5aee9a94c56852570c90056a95d/21d8fd7989fdf78d852570e4001bae68?OpenDocument",
          "name" : "http://www-10.lotus.com/ldd/r5fixlist.nsf/e7dbb5aee9a94c56852570c90056a95d/21d8fd7989fdf78d852570e4001bae68?OpenDocument",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24206",
          "name" : "lotus-long-formula-bo(24206)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in IBM Lotus Notes and Domino Server before 6.5.5, when running on AIX, allows attackers to cause a denial of service (deep recursion leading to stack overflow and crash) via long formulas."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:lotus_domino:6.5.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:lotus_domino:6.5.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:lotus_domino:6.5.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:lotus_domino:6.5.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:lotus_domino:6.5.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:lotus_domino:6.5.4:*:fp1:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:lotus_domino:6.5.4:*:fp2:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:lotus_domino_enterprise_server:6.5.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:lotus_domino_enterprise_server:6.5.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:lotus_notes:6.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:lotus_notes:6.5.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:lotus_notes:6.5.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:lotus_notes:6.5.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:lotus_notes:6.5.4:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-09T11:03Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0119",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "lotus_domino",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.5.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.5.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.5.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.5.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.5.4",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "lotus_domino_enterprise_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.5.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.5.4",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "lotus_notes",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.5.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.5.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.5.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.5.4",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18328",
          "name" : "18328",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/20855",
          "name" : "20855",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1016390",
          "name" : "1016390",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/438461/100/0/threaded",
          "name" : "20060626 SYMSA-2006-006: Lotus Domino SMTP Based Denial of Service",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16158",
          "name" : "16158",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/18020",
          "name" : "18020",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0081",
          "name" : "ADV-2006-0081",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/2564",
          "name" : "ADV-2006-2564",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www-1.ibm.com/support/docview.wss?uid=swg27007054",
          "name" : "http://www-1.ibm.com/support/docview.wss?uid=swg27007054",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www-10.lotus.com/ldd/r5fixlist.nsf/5c087391999d06e7852569280062619d/94a77eb898843aca8525709200001de1?OpenDocument&Highlight=0,JGAN6B6TZ3",
          "name" : "http://www-10.lotus.com/ldd/r5fixlist.nsf/5c087391999d06e7852569280062619d/94a77eb898843aca8525709200001de1?OpenDocument&Highlight=0,JGAN6B6TZ3",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www-10.lotus.com/ldd/r5fixlist.nsf/5c087391999d06e7852569280062619d/9a1650d1a771f3078525702a00420def?OpenDocument&Highlight=0,HSAO6BNL6Y",
          "name" : "http://www-10.lotus.com/ldd/r5fixlist.nsf/5c087391999d06e7852569280062619d/9a1650d1a771f3078525702a00420def?OpenDocument&Highlight=0,HSAO6BNL6Y",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www-10.lotus.com/ldd/r5fixlist.nsf/5c087391999d06e7852569280062619d/d1150fc9c5dec8b18525709200001da6?OpenDocument&Highlight=0,GPKS6C9J67",
          "name" : "http://www-10.lotus.com/ldd/r5fixlist.nsf/5c087391999d06e7852569280062619d/d1150fc9c5dec8b18525709200001da6?OpenDocument&Highlight=0,GPKS6C9J67",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www-10.lotus.com/ldd/r5fixlist.nsf/5c087391999d06e7852569280062619d/de2ab57a5b9547848525701b00420c2c?OpenDocument&Highlight=0,KSPR699NBP",
          "name" : "http://www-10.lotus.com/ldd/r5fixlist.nsf/5c087391999d06e7852569280062619d/de2ab57a5b9547848525701b00420c2c?OpenDocument&Highlight=0,KSPR699NBP",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www-10.lotus.com/ldd/r5fixlist.nsf/5c087391999d06e7852569280062619d/e4deb1cbb011c747852570e4001ba9bb?OpenDocument&Highlight=0,GPKS5YQGPT",
          "name" : "http://www-10.lotus.com/ldd/r5fixlist.nsf/5c087391999d06e7852569280062619d/e4deb1cbb011c747852570e4001ba9bb?OpenDocument&Highlight=0,GPKS5YQGPT",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www-10.lotus.com/ldd/r5fixlist.nsf/5c087391999d06e7852569280062619d/f97fe7cfd9a8113b8525709200001db4?OpenDocument&Highlight=0,GPKS6C9J67",
          "name" : "http://www-10.lotus.com/ldd/r5fixlist.nsf/5c087391999d06e7852569280062619d/f97fe7cfd9a8113b8525709200001db4?OpenDocument&Highlight=0,GPKS6C9J67",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24207",
          "name" : "lotus-multiple-unspecified(24207)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24211",
          "name" : "lotus-web-unspecified-xss(24211)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/27413",
          "name" : "domino-smtp-nrouter-dos(27413)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple unspecified vulnerabilities in IBM Lotus Notes and Domino Server before 6.5.5 have unknown impact and attack vectors, due to \"potential security issues\" as identified by SPR numbers (1) GPKS6C9J67 in Agents, (2) JGAN6B6TZ3 and (3) KSPR699NBP in the Router, (4) GPKS5YQGPT in Security, or (5) HSAO6BNL6Y in the Web Server. NOTE: vector 3 is related to an issue in NROUTER in IBM Lotus Notes and Domino Server before 6.5.4 FP1, 6.5.5, and 7.0, which allows remote attackers to cause a denial of service (CPU consumption) via a crafted vCal meeting request sent via SMTP (aka SPR# KSPR699NBP)."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:lotus_domino:6.5.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:lotus_domino:6.5.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:lotus_domino:6.5.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:lotus_domino:6.5.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:lotus_domino:6.5.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:lotus_domino:6.5.4:*:fp1:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:lotus_domino:6.5.4:*:fp2:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:lotus_domino_enterprise_server:6.5.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:lotus_domino_enterprise_server:6.5.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:lotus_notes:6.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:lotus_notes:6.5.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:lotus_notes:6.5.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:lotus_notes:6.5.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:lotus_notes:6.5.4:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-09T11:03Z",
    "lastModifiedDate" : "2018-10-19T15:42Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0120",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "lotus_domino",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.5.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.5.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.5.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.5.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.5.4",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "lotus_domino_enterprise_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.5.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.5.4",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "lotus_notes",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.5.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.5.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.5.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.5.4",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18328",
          "name" : "18328",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16158",
          "name" : "16158",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0081",
          "name" : "ADV-2006-0081",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www-1.ibm.com/support/docview.wss?uid=swg27007054",
          "name" : "http://www-1.ibm.com/support/docview.wss?uid=swg27007054",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www-10.lotus.com/ldd/r5fixlist.nsf/5c087391999d06e7852569280062619d/258394eaa824f2c08525708a004209d3?OpenDocument",
          "name" : "http://www-10.lotus.com/ldd/r5fixlist.nsf/5c087391999d06e7852569280062619d/258394eaa824f2c08525708a004209d3?OpenDocument",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www-10.lotus.com/ldd/r5fixlist.nsf/e7dbb5aee9a94c56852570c90056a95d/040482aeb1416bb7852570e4001badd6?OpenDocument",
          "name" : "http://www-10.lotus.com/ldd/r5fixlist.nsf/e7dbb5aee9a94c56852570c90056a95d/040482aeb1416bb7852570e4001badd6?OpenDocument",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www-10.lotus.com/ldd/r5fixlist.nsf/e7dbb5aee9a94c56852570c90056a95d/2bb4f466a9e986ae852570e4001babbb?OpenDocument",
          "name" : "http://www-10.lotus.com/ldd/r5fixlist.nsf/e7dbb5aee9a94c56852570c90056a95d/2bb4f466a9e986ae852570e4001babbb?OpenDocument",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www-10.lotus.com/ldd/r5fixlist.nsf/e7dbb5aee9a94c56852570c90056a95d/4118a1f266afb26c852570e4001baf5e?OpenDocument",
          "name" : "http://www-10.lotus.com/ldd/r5fixlist.nsf/e7dbb5aee9a94c56852570c90056a95d/4118a1f266afb26c852570e4001baf5e?OpenDocument",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www-10.lotus.com/ldd/r5fixlist.nsf/e7dbb5aee9a94c56852570c90056a95d/5f166a44ee743b2c852570e4001baf31?OpenDocument",
          "name" : "http://www-10.lotus.com/ldd/r5fixlist.nsf/e7dbb5aee9a94c56852570c90056a95d/5f166a44ee743b2c852570e4001baf31?OpenDocument",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www-10.lotus.com/ldd/r5fixlist.nsf/e7dbb5aee9a94c56852570c90056a95d/ad0dd14aa109f96b852570e4001bb08c?OpenDocument",
          "name" : "http://www-10.lotus.com/ldd/r5fixlist.nsf/e7dbb5aee9a94c56852570c90056a95d/ad0dd14aa109f96b852570e4001bb08c?OpenDocument",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www-10.lotus.com/ldd/r5fixlist.nsf/e7dbb5aee9a94c56852570c90056a95d/ced5f873baea4e8b852570e4001baa6d?OpenDocument",
          "name" : "http://www-10.lotus.com/ldd/r5fixlist.nsf/e7dbb5aee9a94c56852570c90056a95d/ced5f873baea4e8b852570e4001baa6d?OpenDocument",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24212",
          "name" : "lotus-outofoffice-dos(24212)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24213",
          "name" : "lotus-compact-dos(24213)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24214",
          "name" : "lotus-bmp-dos(24214)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24215",
          "name" : "lotus-delete-attachment-dos(24215)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24216",
          "name" : "lotus-certificate-parsing-dos(24216)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24217",
          "name" : "lotus-ssl-keyring-dos(24217)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple unspecified vulnerabilities in IBM Lotus Notes and Domino Server before 6.5.5 allow attackers to cause a denial of service (application crash) via multiple vectors, involving (1) a malformed message sent to an \"Out Of Office\" agent (SPR LPEE6DMQWJ), (2) the compact command (RTIN5U2SAJ), (3) malformed bitmap images (MYAA6FH5HW), (4) the \"Delete Attachment\" action (YPHG6844LD), (5) parsing certificates from a remote Certificate Table (AELE6DZFJW), and (6) creating a SSL key ring with the Domino Administration client (NSUA4FQPTN)."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:lotus_domino:6.5.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:lotus_domino:6.5.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:lotus_domino:6.5.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:lotus_domino:6.5.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:lotus_domino:6.5.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:lotus_domino:6.5.4:*:fp1:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:lotus_domino:6.5.4:*:fp2:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:lotus_domino_enterprise_server:6.5.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:lotus_domino_enterprise_server:6.5.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:lotus_notes:6.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:lotus_notes:6.5.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:lotus_notes:6.5.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:lotus_notes:6.5.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:lotus_notes:6.5.4:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-09T11:03Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0121",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "lotus_domino",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.5.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.5.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.5.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.5.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.5.4",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "lotus_domino_enterprise_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.5.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.5.4",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "lotus_notes",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.5.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.5.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.5.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.5.4",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18328",
          "name" : "18328",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16158",
          "name" : "16158",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0081",
          "name" : "ADV-2006-0081",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www-1.ibm.com/support/docview.wss?uid=swg27007054",
          "name" : "http://www-1.ibm.com/support/docview.wss?uid=swg27007054",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www-10.lotus.com/ldd/r5fixlist.nsf/5c087391999d06e7852569280062619d/20f66e356a76c90f8525702a00420e08?OpenDocument&Highlight=0,MKIN67MQVW",
          "name" : "http://www-10.lotus.com/ldd/r5fixlist.nsf/5c087391999d06e7852569280062619d/20f66e356a76c90f8525702a00420e08?OpenDocument&Highlight=0,MKIN67MQVW",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www-10.lotus.com/ldd/r5fixlist.nsf/5c087391999d06e7852569280062619d/2221243535d88a2b8525701b00420cd6?OpenDocument&Highlight=0,MKIN693QUT",
          "name" : "http://www-10.lotus.com/ldd/r5fixlist.nsf/5c087391999d06e7852569280062619d/2221243535d88a2b8525701b00420cd6?OpenDocument&Highlight=0,MKIN693QUT",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24223",
          "name" : "lotus-ssl-handshake-dos(24223)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple memory leaks in IBM Lotus Notes and Domino Server before 6.5.5 allow attackers to cause a denial of service (memory consumption and crash) via unknown vectors related to (1) unspecified vectors during the SSL handshake (SPR# MKIN67MQVW), (2) the stash file during the SSL handshake (SPR# MKIN693QUT), and possibly other vectors. NOTE: due to insufficient information in the original vendor advisory, it is not clear whether there is an attacker role in other memory leaks that are specified in the advisory."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:lotus_domino:6.5.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:lotus_domino:6.5.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:lotus_domino:6.5.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:lotus_domino:6.5.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:lotus_domino:6.5.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:lotus_domino:6.5.4:*:fp1:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:lotus_domino:6.5.4:*:fp2:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:lotus_domino_enterprise_server:6.5.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:lotus_domino_enterprise_server:6.5.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:lotus_notes:6.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:lotus_notes:6.5.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:lotus_notes:6.5.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:lotus_notes:6.5.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:lotus_notes:6.5.4:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.8
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-09T11:03Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0122",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "aquifer_cms",
            "product" : {
              "product_data" : [ {
                "product_name" : "aquifer_cms",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://attrition.org/pipermail/vim/2006-January/000509.html",
          "name" : "20060124 vendor ack/fix: Aquifer CMS Index.asp Keyword Variable XSS (fwd)",
          "refsource" : "VIM",
          "tags" : [ ]
        }, {
          "url" : "http://osvdb.org/ref/22/22247-aquifer.txt",
          "name" : "http://osvdb.org/ref/22/22247-aquifer.txt",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://secunia.com/advisories/18326",
          "name" : "18326",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/22247",
          "name" : "22247",
          "refsource" : "OSVDB",
          "tags" : [ "Exploit", "Patch" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16162",
          "name" : "16162",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0074",
          "name" : "ADV-2006-0074",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in Public/Index.asp in Aquifer CMS allows remote attackers to inject arbitrary web script or HTML via the Keyword parameter."
        }, {
          "lang" : "en",
          "value" : "Vendor provided solution:\r\n\r\n\"Liquid Development has identified this vulnerability in all shipping versions of AquiferCMS and coded a software fix. The fix will be included in all releases of AquiferCMS built on or after January 24, 2006. Customers should contact Liquid Development to obtain the fix for this vulnerability.  For more information visit www.aquifercms.com.\" \r\n"
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:aquifer_cms:aquifer_cms:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-09T11:03Z",
    "lastModifiedDate" : "2011-03-08T02:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0123",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "adn_forum",
            "product" : {
              "product_data" : [ {
                "product_name" : "adn_forum",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0b",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://evuln.com/vulns/15/summary.html",
          "name" : "http://evuln.com/vulns/15/summary.html",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18300",
          "name" : "18300",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1015445",
          "name" : "1015445",
          "refsource" : "SECTRACK",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.osvdb.org/22240",
          "name" : "22240",
          "refsource" : "OSVDB",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.osvdb.org/22241",
          "name" : "22241",
          "refsource" : "OSVDB",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/420990/100/0/threaded",
          "name" : "20060105 [eVuln] ADNForum Multiple Vulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16157",
          "name" : "16157",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0077",
          "name" : "ADV-2006-0077",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple SQL injection vulnerabilities in ADN Forum 1.0b allow remote attackers to execute arbitrary SQL commands via the (1) fid parameter in index.php and (2) pagid parameter in verpag.php, and possibly other vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adn_forum:adn_forum:1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adn_forum:adn_forum:1.0b:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-09T11:03Z",
    "lastModifiedDate" : "2018-10-19T15:42Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0124",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "adn_forum",
            "product" : {
              "product_data" : [ {
                "product_name" : "adn_forum",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0b",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://evuln.com/vulns/15/summary.html",
          "name" : "http://evuln.com/vulns/15/summary.html",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18300",
          "name" : "18300",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1015445",
          "name" : "1015445",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/22242",
          "name" : "22242",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/420990/100/0/threaded",
          "name" : "20060105 [eVuln] ADNForum Multiple Vulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16157",
          "name" : "16157",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0077",
          "name" : "ADV-2006-0077",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in crear.php in ADN Forum 1.0b allows remote attackers to inject arbitrary web script or HTML via the titulo parameter, which is used by the \"Topic name\" field."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adn_forum:adn_forum:1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adn_forum:adn_forum:1.0b:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-09T11:03Z",
    "lastModifiedDate" : "2018-10-19T15:42Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0125",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "appserv_open_project",
            "product" : {
              "product_data" : [ {
                "product_name" : "appserv",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.4.5",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18163",
          "name" : "18163",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/22228",
          "name" : "22228",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16166",
          "name" : "16166",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0053",
          "name" : "ADV-2006-0053",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in appserv/main.php in AppServ 2.4.5 allows remote attackers to include arbitrary files via the appserv_root parameter.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.  There is not enough detail from these third party sources to know whether this is directory traversal, remote file include, or another issue."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:appserv_open_project:appserv:2.4.5:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-09T11:03Z",
    "lastModifiedDate" : "2011-03-08T02:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0126",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "rxvt-unicode",
            "product" : {
              "product_data" : [ {
                "product_name" : "rxvt-unicode",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.2",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://dist.schmorp.de/rxvt-unicode/Changes",
          "name" : "http://dist.schmorp.de/rxvt-unicode/Changes",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18301",
          "name" : "18301",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/22223",
          "name" : "22223",
          "refsource" : "OSVDB",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0052",
          "name" : "ADV-2006-0052",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "rxvt-unicode before 6.3, on certain platforms that use openpty and non-Unix pty devices such as Linux and most BSD platforms, does not maintain the intended permissions of tty devices, which allows local users to gain read and write access to the devices."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rxvt-unicode:rxvt-unicode:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "6.2"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 4.6
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 3.9,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-09T11:03Z",
    "lastModifiedDate" : "2011-03-08T02:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0127",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "rockliffe",
            "product" : {
              "product_data" : [ {
                "product_name" : "mailsite",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.1.22.0",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.grok.org.uk/pipermail/full-disclosure/2006-January/040969.html",
          "name" : "20060104 Rockliffe Directory Transversal Vulnerability",
          "refsource" : "FULLDISC",
          "tags" : [ "Exploit", "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://lists.grok.org.uk/pipermail/full-disclosure/2006-January/041039.html",
          "name" : "20060105 Re: Rockliffe Directory Transversal Vulnerability",
          "refsource" : "FULLDISC",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18318",
          "name" : "18318",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/22229",
          "name" : "22229",
          "refsource" : "OSVDB",
          "tags" : [ "Exploit", "Patch" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0055",
          "name" : "ADV-2006-0055",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://zur.homelinux.com/Advisories/RockliffeMailsiteDirTransveral.txt",
          "name" : "http://zur.homelinux.com/Advisories/RockliffeMailsiteDirTransveral.txt",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Patch", "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Directory traversal vulnerability in the IMAP service of Rockliffe MailSite before 6.1.22.1 allows remote authenticated users to rename the folders of other users via a .. (dot dot) in the RENAME command."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rockliffe:mailsite:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "6.1.22.0"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-09T11:03Z",
    "lastModifiedDate" : "2011-03-08T02:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0128",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "rockliffe",
            "product" : {
              "product_data" : [ {
                "product_name" : "mailsite",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.1.22.0",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.grok.org.uk/pipermail/full-disclosure/2006-January/040969.html",
          "name" : "20060104 Rockliffe Directory Transversal Vulnerability",
          "refsource" : "FULLDISC",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://zur.homelinux.com/Advisories/RockliffeMailsiteDirTransveral.txt",
          "name" : "http://zur.homelinux.com/Advisories/RockliffeMailsiteDirTransveral.txt",
          "refsource" : "MISC",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39991",
          "name" : "rockliffe-imap-unspecified-bo(39991)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Buffer overflow in the IMAP service of Rockliffe MailSite before 6.1.22.1 allows remote attackers to have an unknown impact via unknown attack vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rockliffe:mailsite:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "6.1.22.0"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-09T11:03Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0129",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "rockliffe",
            "product" : {
              "product_data" : [ {
                "product_name" : "mailsite",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.0.3.1",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.grok.org.uk/pipermail/full-disclosure/2006-January/040970.html",
          "name" : "20060104 Rockliffe Mailsite User Enumeration Flaw",
          "refsource" : "FULLDISC",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18318",
          "name" : "18318",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/22230",
          "name" : "22230",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0055",
          "name" : "ADV-2006-0055",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://zur.homelinux.com/Advisories/RockliffeMailsiteUserEnum.txt",
          "name" : "http://zur.homelinux.com/Advisories/RockliffeMailsiteUserEnum.txt",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Mail Management Agent (MAILMA) (aka Mail Management Server) in Rockliffe MailSite 7.0.3.1 and earlier generates different responses depending on whether or not a username is valid, which allows remote attackers to enumerate valid usernames via user requests to TCP port 106."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rockliffe:mailsite:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "7.0.3.1"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-09T11:03Z",
    "lastModifiedDate" : "2011-03-08T02:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0130",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "rockliffe",
            "product" : {
              "product_data" : [ {
                "product_name" : "mailsite",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.0.3.1",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.grok.org.uk/pipermail/full-disclosure/2006-January/040970.html",
          "name" : "20060104 Rockliffe Mailsite User Enumeration Flaw",
          "refsource" : "FULLDISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://zur.homelinux.com/Advisories/RockliffeMailsiteUserEnum.txt",
          "name" : "http://zur.homelinux.com/Advisories/RockliffeMailsiteUserEnum.txt",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Mail Management Agent (MAILMA) (aka Mail Management Server) in Rockliffe MailSite 7.0.3.1 and earlier allows remote attackers to attempt authentication with an unlimited number of user account names and passwords without denying connections, limiting the rate of connections, or locking out an account."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rockliffe:mailsite:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "7.0.3.1"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-09T11:03Z",
    "lastModifiedDate" : "2008-09-05T20:58Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0131",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "boastmachine",
            "product" : {
              "product_data" : [ {
                "product_name" : "boastmachine",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://echo.or.id/adv/adv26-K-159-2006.txt",
          "name" : "http://echo.or.id/adv/adv26-K-159-2006.txt",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/420969/100/0/threaded",
          "name" : "20060105 [ECHO_ADV_25$2006] Full path disclosure on boastMachine v3.1",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "boastMachine 3.1 allows remote attackers to obtain sensitive information via a direct request to (1) footer.php and (2) side_menu.php, which reveals the path in an error message."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:boastmachine:boastmachine:3.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-09T11:03Z",
    "lastModifiedDate" : "2018-10-19T15:42Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0132",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "webftp",
            "product" : {
              "product_data" : [ {
                "product_name" : "webftp",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.2.6",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18355",
          "name" : "18355",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/420973/100/0/threaded",
          "name" : "20060104 SysCP WebFTP local file inclusion vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16175",
          "name" : "16175",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0090",
          "name" : "ADV-2006-0090",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24018",
          "name" : "webftp-language-file-include(24018)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Directory traversal vulnerability in webftp.php in SysCP WebFTP 1.2.6 and possibly earlier allows remote attackers to include and execute arbitrary local PHP scripts, and possibly read other types of files, via a .. (dot dot) and a trailing null in the webftp_language parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:webftp:webftp:1.2.6:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-09T11:03Z",
    "lastModifiedDate" : "2018-10-19T15:42Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0133",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "aix",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.3_ml03",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://securitytracker.com/id?1015429",
          "name" : "1015429",
          "refsource" : "SECTRACK",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/420589/100/0/threaded",
          "name" : "20060101 [xfocus-SD-060101]AIX getCommand&getShell two vulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16102",
          "name" : "16102",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16103",
          "name" : "16103",
          "refsource" : "BID",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple directory traversal vulnerabilities in AIX 5.3 ML03 allow local users to determine the existence of files and read partial contents of certain files via a .. (dot dot) in the argument to (1) getCommand.new (aka getCommand) and (2) getShell, a different vulnerability than CVE-2005-4273."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:ibm:aix:5.3_ml03:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:P/I:P/A:N",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 3.6
        },
        "severity" : "LOW",
        "exploitabilityScore" : 3.9,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-09T11:03Z",
    "lastModifiedDate" : "2018-10-19T15:42Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0134",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "thewebforum",
            "product" : {
              "product_data" : [ {
                "product_name" : "thewebforum",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.2.1",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://evuln.com/vulns/17/exploit.html",
          "name" : "http://evuln.com/vulns/17/exploit.html",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://evuln.com/vulns/17/summary.html",
          "name" : "http://evuln.com/vulns/17/summary.html",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://secunia.com/advisories/18392",
          "name" : "18392",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1015450",
          "name" : "1015450",
          "refsource" : "SECTRACK",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.osvdb.org/22295",
          "name" : "22295",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/421039/100/0/threaded",
          "name" : "20060106 [eVuln] TheWebForum Script Insertion and Authentication Bypass",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16161",
          "name" : "16161",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0093",
          "name" : "ADV-2006-0093",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24007",
          "name" : "thewebforum-register-xss(24007)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in register.php in TheWebForum (twf) 1.2.1 allows remote attackers to inject arbitrary web script or HTML via the www parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:thewebforum:thewebforum:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.2.1"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-09T11:03Z",
    "lastModifiedDate" : "2018-10-19T15:42Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0135",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "thewebforum",
            "product" : {
              "product_data" : [ {
                "product_name" : "thewebforum",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.2.1",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://evuln.com/vulns/17/exploit.html",
          "name" : "http://evuln.com/vulns/17/exploit.html",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://evuln.com/vulns/17/summary.html",
          "name" : "http://evuln.com/vulns/17/summary.html",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://secunia.com/advisories/18392",
          "name" : "18392",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/321",
          "name" : "321",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1015450",
          "name" : "1015450",
          "refsource" : "SECTRACK",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.osvdb.org/22294",
          "name" : "22294",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/421039/100/0/threaded",
          "name" : "20060106 [eVuln] TheWebForum Script Insertion and Authentication Bypass",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16161",
          "name" : "16161",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0093",
          "name" : "ADV-2006-0093",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24027",
          "name" : "thewebforum-login-sql-injection(24027)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in login.php in TheWebForum (twf) 1.2.1 allows remote attackers to execute arbitrary SQL commands and bypass login authentication via the username parameter (aka the u variable)."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:thewebforum:thewebforum:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.2.1"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-09T11:03Z",
    "lastModifiedDate" : "2018-10-19T15:42Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0136",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "phanatic_softwares",
            "product" : {
              "product_data" : [ {
                "product_name" : "chimera_web_portal",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://evuln.com/vulns/7/exploit.html",
          "name" : "http://evuln.com/vulns/7/exploit.html",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://evuln.com/vulns/7/summary.html",
          "name" : "http://evuln.com/vulns/7/summary.html",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/420669/100/0/threaded",
          "name" : "20060101 [eVuln] Chimera Web Portal System Multiple Vulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16113",
          "name" : "16113",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0025",
          "name" : "ADV-2006-0025",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple cross-site scripting (XSS) vulnerabilities in the guestbook module in modules.php in Phanatic Softwares Chimera Web Portal System 0.2 allow remote attackers to inject arbitrary web script or HTML via the (1) comment_poster, (2) comment_poster_email, (3) comment_poster_homepage, and (4) comment_text parameters."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:phanatic_softwares:chimera_web_portal:0.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-09T11:03Z",
    "lastModifiedDate" : "2018-10-19T15:42Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0137",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "phanatic_softwares",
            "product" : {
              "product_data" : [ {
                "product_name" : "chimera_web_portal",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://evuln.com/vulns/7/exploit.html",
          "name" : "http://evuln.com/vulns/7/exploit.html",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://evuln.com/vulns/7/summary.html",
          "name" : "http://evuln.com/vulns/7/summary.html",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.osvdb.org/22420",
          "name" : "22420",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/420669/100/0/threaded",
          "name" : "20060101 [eVuln] Chimera Web Portal System Multiple Vulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16113",
          "name" : "16113",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0025",
          "name" : "ADV-2006-0025",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/23963",
          "name" : "chimera-linkcategory-sql-injection(23963)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in linkcategory.php in Phanatic Softwares Chimera Web Portal System 0.2 allows remote attackers to execute arbitrary SQL commands via the id parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:phanatic_softwares:chimera_web_portal:0.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-09T11:03Z",
    "lastModifiedDate" : "2018-10-19T15:42Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0138",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "amsn",
            "product" : {
              "product_data" : [ {
                "product_name" : "amsn",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.osvdb.org/22186",
          "name" : "22186",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securiteam.com/exploits/5JP090KHFQ.html",
          "name" : "http://www.securiteam.com/exploits/5JP090KHFQ.html",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "aMSN (aka Alvaro's Messenger) allows remote attackers to cause a denial of service (client hang and termination of client's instant-messaging session) by repeatedly sending crafted data to the default file-transfer port (TCP 6891)."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:amsn:amsn:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-09T11:03Z",
    "lastModifiedDate" : "2008-09-05T20:58Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0139",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "pd9_software",
            "product" : {
              "product_data" : [ {
                "product_name" : "megabbs",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18342",
          "name" : "18342",
          "refsource" : "SECUNIA",
          "tags" : [ "Exploit", "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1015452",
          "name" : "1015452",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.hamid.ir/security/megabbs.txt",
          "name" : "http://www.hamid.ir/security/megabbs.txt",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.pd9soft.com/megabbs/forums/thread-view.asp?tid=4924",
          "name" : "http://www.pd9soft.com/megabbs/forums/thread-view.asp?tid=4924",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16168",
          "name" : "16168",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0095",
          "name" : "ADV-2006-0095",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24050",
          "name" : "megabbs-sendprivatemessage-disclosure(24050)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The send-private-message functionality (send-private-message.asp) in PD9 Software MegaBBS 2.1 allows remote attackers to read private messages of other users via a modified replyid parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pd9_software:megabbs:2.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pd9_software:megabbs:2.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-09T18:03Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0140",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "navboard",
            "product" : {
              "product_data" : [ {
                "product_name" : "navboard",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "16",
                    "version_affected" : "="
                  }, {
                    "version_value" : "17",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://evuln.com/vulns/19/summary.html",
          "name" : "http://evuln.com/vulns/19/summary.html",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18345",
          "name" : "18345",
          "refsource" : "SECUNIA",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/22277",
          "name" : "22277",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/421149/100/0/threaded",
          "name" : "20060107 [eVuln] NavBoard BBcode XSS Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16165",
          "name" : "16165",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0092",
          "name" : "ADV-2006-0092",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24021",
          "name" : "navboard-post-xss(24021)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in post.php in NavBoard V16 Stable(2.6.0) and V17beta2 allows remote attackers to inject arbitrary web script or HTML via the (1) b, (2) textlarge, and (3) url bbcode tags."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:navboard:navboard:16:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:navboard:navboard:17:beta2:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2006-01-09T19:07Z",
    "lastModifiedDate" : "2018-10-19T15:42Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0141",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "eudora",
            "product" : {
              "product_data" : [ {
                "product_name" : "internet_mail_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.2.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.2.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.2.8",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18356",
          "name" : "18356",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.eudora.co.nz/updates.html",
          "name" : "http://www.eudora.co.nz/updates.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16179",
          "name" : "16179",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0099",
          "name" : "ADV-2006-0099",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24032",
          "name" : "eims-ntlm-auth-dos(24032)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24033",
          "name" : "eims-corrupted-mail-dos(24033)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Qualcomm Eudora Internet Mail Server (EIMS) before 3.2.8 allows remote attackers to cause a denial of service (crash) via (1) malformed NTLM authentication requests, or a malformed (2) Incoming Mail X or (3) Temporary Mail file."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:eudora:internet_mail_server:3.2.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:eudora:internet_mail_server:3.2.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:eudora:internet_mail_server:3.2.8:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-09T19:07Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0142",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "andromeda_software",
            "product" : {
              "product_data" : [ {
                "product_name" : "andromeda",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.9.3.4",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18359",
          "name" : "18359",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16183",
          "name" : "16183",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0096",
          "name" : "ADV-2006-0096",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24031",
          "name" : "andromeda-script-xss(24031)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in andromeda.php in Andromeda 1.9.3.4 and earlier allows remote attackers to inject arbitrary web script or HTML via the s parameter.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:andromeda_software:andromeda:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.9.3.4"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-09T19:07Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0143",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "windows_2000",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_2003_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "datacenter_64-bit",
                    "version_affected" : "="
                  }, {
                    "version_value" : "enterprise",
                    "version_affected" : "="
                  }, {
                    "version_value" : "enterprise_64-bit",
                    "version_affected" : "="
                  }, {
                    "version_value" : "r2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "standard",
                    "version_affected" : "="
                  }, {
                    "version_value" : "standard_64-bit",
                    "version_affected" : "="
                  }, {
                    "version_value" : "web",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_98",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_98se",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_me",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_xp",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-399"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://blogs.technet.com/msrc/archive/2006/01/09/417198.aspx",
          "name" : "http://blogs.technet.com/msrc/archive/2006/01/09/417198.aspx",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://lostmon.blogspot.com/2007/08/windows-extended-file-attributes-buffer.html",
          "name" : "http://lostmon.blogspot.com/2007/08/windows-extended-file-attributes-buffer.html",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1015453",
          "name" : "1015453",
          "refsource" : "SECTRACK",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/421257/100/0/threaded",
          "name" : "20060107 Microsoft Windows GRE WMF Format Multiple Memory Overrun Vulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/421258/100/0/threaded",
          "name" : "20060109 [UPDATE]Microsoft Windows GRE WMF Format Multiple Unauthorized Memory Access Vulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16167",
          "name" : "16167",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0115",
          "name" : "ADV-2006-0115",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24044",
          "name" : "win-gre-wmf-dos(24044)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Microsoft Windows Graphics Rendering Engine (GRE) allows remote attackers to corrupt memory and cause a denial of service (crash) via a WMF file containing (1) ExtCreateRegion or (2) ExtEscape function calls with arguments with inconsistent lengths."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2000:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2000:*:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2000:*:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2000:*:sp3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2000:*:sp4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:datacenter_64-bit:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:enterprise:*:64-bit:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:enterprise:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:enterprise_64-bit:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:enterprise_64-bit:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:r2:*:64-bit:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:r2:*:datacenter_64-bit:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:r2:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:standard:*:64-bit:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:standard:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:standard_64-bit:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:web:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:web:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_98:*:gold:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_98se:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_me:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_xp:*:*:64-bit:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_xp:*:*:home:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_xp:*:*:media_center:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_xp:*:gold:professional:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_xp:*:sp1:home:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_xp:*:sp1:media_center:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_xp:*:sp2:home:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_xp:*:sp2:media_center:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_xp:*:sp2:tablet_pc:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-09T20:03Z",
    "lastModifiedDate" : "2019-04-30T14:27Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0144",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apache2triad",
            "product" : {
              "product_data" : [ {
                "product_name" : "apache2triad",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "php",
            "product" : {
              "product_data" : [ {
                "product_name" : "pear",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.2.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-94"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://apache2triad.net/forums/viewtopic.php?p=14670",
          "name" : "http://apache2triad.net/forums/viewtopic.php?p=14670",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18390",
          "name" : "18390",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/421469/100/0/threaded",
          "name" : "20060109 New PEAR / Apache2Triad Exploit",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16174",
          "name" : "16174",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0148",
          "name" : "ADV-2006-0148",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24076",
          "name" : "gopear-proxy-redirection(24076)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The proxy server feature in go-pear.php in PHP PEAR 0.2.2, as used in Apache2Triad, allows remote attackers to execute arbitrary PHP code by redirecting go-pear.php to a malicious proxy server that provides a modified version of Tar.php with a malicious extractModify function."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache2triad:apache2triad:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:pear:0.2.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-09T23:03Z",
    "lastModifiedDate" : "2018-10-19T15:42Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0145",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "netbsd",
            "product" : {
              "product_data" : [ {
                "product_name" : "netbsd",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.6.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.6.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2006-001.txt.asc",
          "name" : "NetBSD-SA2006-001",
          "refsource" : "NETBSD",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18388",
          "name" : "18388",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18712",
          "name" : "18712",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/405",
          "name" : "405",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/22293",
          "name" : "22293",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/423827/100/0/threaded",
          "name" : "20060202 [SLAB] NetBSD / OpenBSD kernfs_xread patch evasion",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16173",
          "name" : "16173",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.securitylab.net/research/2006/02/advisory_netbsd_openbsd_kernfs.html",
          "name" : "http://www.securitylab.net/research/2006/02/advisory_netbsd_openbsd_kernfs.html",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24035",
          "name" : "netbsd-kernfs-memory-disclosure(24035)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The kernfs_xread function in kernfs in NetBSD 1.6 through 2.1, and OpenBSD 3.8, does not properly validate file offsets against negative 32-bit values that occur as a result of truncation, which allows local users to read arbitrary kernel memory and gain privileges via the lseek system call."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:netbsd:netbsd:1.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:netbsd:netbsd:1.6:beta:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:netbsd:netbsd:1.6.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:netbsd:netbsd:1.6.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:netbsd:netbsd:2.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:netbsd:netbsd:2.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:netbsd:netbsd:2.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:netbsd:netbsd:2.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:netbsd:netbsd:2.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 4.6
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 3.9,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-09T23:03Z",
    "lastModifiedDate" : "2018-10-19T15:42Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0146",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "john_lim",
            "product" : {
              "product_data" : [ {
                "product_name" : "adodb",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.66",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.68",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "mantis",
            "product" : {
              "product_data" : [ {
                "product_name" : "mantis",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.19.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.0_rc4",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "mediabeez",
            "product" : {
              "product_data" : [ {
                "product_name" : "mediabeez",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "moodle",
            "product" : {
              "product_data" : [ {
                "product_name" : "moodle",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.5.3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "postnuke_software_foundation",
            "product" : {
              "product_data" : [ {
                "product_name" : "postnuke",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.761",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "the_cacti_group",
            "product" : {
              "product_data" : [ {
                "product_name" : "cacti",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.8.6g",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://retrogod.altervista.org/phpopenchat_30x_sql_xpl.html",
          "name" : "http://retrogod.altervista.org/phpopenchat_30x_sql_xpl.html",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://secunia.com/advisories/17418",
          "name" : "17418",
          "refsource" : "SECUNIA",
          "tags" : [ "Exploit", "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18233",
          "name" : "18233",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18254",
          "name" : "18254",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18260",
          "name" : "18260",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18267",
          "name" : "18267",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18276",
          "name" : "18276",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18720",
          "name" : "18720",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/19555",
          "name" : "19555",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/19563",
          "name" : "19563",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/19590",
          "name" : "19590",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/19591",
          "name" : "19591",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/19600",
          "name" : "19600",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/19691",
          "name" : "19691",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/19699",
          "name" : "19699",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24954",
          "name" : "24954",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/secunia_research/2005-64/advisory/",
          "name" : "http://secunia.com/secunia_research/2005-64/advisory/",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/713",
          "name" : "713",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2006/dsa-1029",
          "name" : "DSA-1029",
          "refsource" : "DEBIAN",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.debian.org/security/2006/dsa-1030",
          "name" : "DSA-1030",
          "refsource" : "DEBIAN",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.debian.org/security/2006/dsa-1031",
          "name" : "DSA-1031",
          "refsource" : "DEBIAN",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.gentoo.org/security/en/glsa/glsa-200604-07.xml",
          "name" : "GLSA-200604-07",
          "refsource" : "GENTOO",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.maxdev.com/Article550.phtml",
          "name" : "http://www.maxdev.com/Article550.phtml",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/22290",
          "name" : "22290",
          "refsource" : "OSVDB",
          "tags" : [ "Exploit", "Patch" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/423784/100/0/threaded",
          "name" : "20060202 Bug for libs in php link directory 2.0",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/430448/100/0/threaded",
          "name" : "20060409 PhpOpenChat 3.0.x ADODB Server.php \"sql\" SQL injection",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/466171/100/0/threaded",
          "name" : "20070418 MediaBeez Sql query Execution .. Wear isn't ?? :)",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16187",
          "name" : "16187",
          "refsource" : "BID",
          "tags" : [ "Exploit", "Patch" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0101",
          "name" : "ADV-2006-0101",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0102",
          "name" : "ADV-2006-0102",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0103",
          "name" : "ADV-2006-0103",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0104",
          "name" : "ADV-2006-0104",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0105",
          "name" : "ADV-2006-0105",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0370",
          "name" : "ADV-2006-0370",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0447",
          "name" : "ADV-2006-0447",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/1304",
          "name" : "ADV-2006-1304",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/1305",
          "name" : "ADV-2006-1305",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/1419",
          "name" : "ADV-2006-1419",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.xaraya.com/index.php/news/569",
          "name" : "http://www.xaraya.com/index.php/news/569",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24051",
          "name" : "adodb-server-command-execution(24051)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The server.php test script in ADOdb for PHP before 4.70, as used in multiple products including (1) Mantis, (2) PostNuke, (3) Moodle, (4) Cacti, (5) Xaraya, (6) PHPOpenChat, (7) MAXdev MD-Pro, and (8) MediaBeez, when the MySQL root password is empty, allows remote attackers to execute arbitrary SQL commands via the sql parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:john_lim:adodb:4.66:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:john_lim:adodb:4.68:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.19.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:1.0.0_rc4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mediabeez:mediabeez:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:moodle:moodle:1.5.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postnuke_software_foundation:postnuke:0.761:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:the_cacti_group:cacti:0.8.6g:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-09T23:03Z",
    "lastModifiedDate" : "2018-10-19T15:42Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0147",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "john_lim",
            "product" : {
              "product_data" : [ {
                "product_name" : "adodb",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.66",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.68",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "mantis",
            "product" : {
              "product_data" : [ {
                "product_name" : "mantis",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.19.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.0_rc4",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "moodle",
            "product" : {
              "product_data" : [ {
                "product_name" : "moodle",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.5.3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "postnuke_software_foundation",
            "product" : {
              "product_data" : [ {
                "product_name" : "postnuke",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.761",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "the_cacti_group",
            "product" : {
              "product_data" : [ {
                "product_name" : "cacti",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.8.6g",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://retrogod.altervista.org/phpopenchat_30x_sql_xpl.html",
          "name" : "http://retrogod.altervista.org/phpopenchat_30x_sql_xpl.html",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://retrogod.altervista.org/simplog_092_incl_xpl.html",
          "name" : "http://retrogod.altervista.org/simplog_092_incl_xpl.html",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://secunia.com/advisories/17418",
          "name" : "17418",
          "refsource" : "SECUNIA",
          "tags" : [ "Exploit", "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18233",
          "name" : "18233",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18254",
          "name" : "18254",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18260",
          "name" : "18260",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18267",
          "name" : "18267",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18276",
          "name" : "18276",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/19555",
          "name" : "19555",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/19590",
          "name" : "19590",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/19591",
          "name" : "19591",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/19600",
          "name" : "19600",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/19628",
          "name" : "19628",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/19691",
          "name" : "19691",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/secunia_research/2005-64/advisory/",
          "name" : "http://secunia.com/secunia_research/2005-64/advisory/",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.debian.org/security/2006/dsa-1029",
          "name" : "DSA-1029",
          "refsource" : "DEBIAN",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.debian.org/security/2006/dsa-1030",
          "name" : "DSA-1030",
          "refsource" : "DEBIAN",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.debian.org/security/2006/dsa-1031",
          "name" : "DSA-1031",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.gentoo.org/security/en/glsa/glsa-200604-07.xml",
          "name" : "GLSA-200604-07",
          "refsource" : "GENTOO",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/22291",
          "name" : "22291",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/430448/100/0/threaded",
          "name" : "20060409 PhpOpenChat 3.0.x ADODB Server.php \"sql\" SQL injection",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/430743/100/0/threaded",
          "name" : "20060412 Simplog <=0.9.2 multiple vulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0101",
          "name" : "ADV-2006-0101",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0102",
          "name" : "ADV-2006-0102",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0103",
          "name" : "ADV-2006-0103",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0104",
          "name" : "ADV-2006-0104",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/1305",
          "name" : "ADV-2006-1305",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/1332",
          "name" : "ADV-2006-1332",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24052",
          "name" : "adodb-tmssql-command-execution(24052)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/1663",
          "name" : "1663",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Dynamic code evaluation vulnerability in tests/tmssql.php test script in ADOdb for PHP before 4.70, as used in multiple products including (1) Mantis, (2) PostNuke, (3) Moodle, (4) Cacti, (5) Xaraya, (6) PhpOpenChat, possibly (7) MAXdev MD-Pro, and (8) Simplog, allows remote attackers to execute arbitrary PHP functions via the do parameter, which is saved in a variable that is then executed as a function, as demonstrated using phpinfo."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:john_lim:adodb:4.66:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:john_lim:adodb:4.68:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.19.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:1.0.0_rc4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:moodle:moodle:1.5.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postnuke_software_foundation:postnuke:0.761:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:the_cacti_group:cacti:0.8.6g:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-09T23:03Z",
    "lastModifiedDate" : "2018-10-19T15:42Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0148",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "netsarang",
            "product" : {
              "product_data" : [ {
                "product_name" : "xlpd",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://securitytracker.com/id?1015444",
          "name" : "1015444",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.ipomonis.com/advisories/xlpd.txt",
          "name" : "http://www.ipomonis.com/advisories/xlpd.txt",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16164",
          "name" : "16164",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24041",
          "name" : "xlpd-connection-dos(24041)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "NetSarang Xlpd 2.1 allows remote attackers to cause a denial of service (crash) via a large number of connections from the same IP address."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:netsarang:xlpd:2.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-09T23:03Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0149",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "simpbook",
            "product" : {
              "product_data" : [ {
                "product_name" : "simpbook",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.grok.org.uk/pipermail/full-disclosure/2006-January/041127.html",
          "name" : "20060106 SimpBook \"message\" Remote Cross-Site Scripting Vulnerability",
          "refsource" : "FULLDISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1015451",
          "name" : "1015451",
          "refsource" : "SECTRACK",
          "tags" : [ "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in SimpBook 1.0, with html_enable on (the default), allows remote attackers to inject arbitrary web script or HTML via the message field."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:simpbook:simpbook:1.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-09T23:03Z",
    "lastModifiedDate" : "2008-09-05T20:58Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0150",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "dave_carrigan",
            "product" : {
              "product_data" : [ {
                "product_name" : "auth_ldap",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.2.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.6.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-134"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18382",
          "name" : "18382",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18405",
          "name" : "18405",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18412",
          "name" : "18412",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18568",
          "name" : "18568",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1015456",
          "name" : "1015456",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2006/dsa-952",
          "name" : "DSA-952",
          "refsource" : "DEBIAN",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.digitalarmaments.com/2006090173928420.html",
          "name" : "http://www.digitalarmaments.com/2006090173928420.html",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2006-0179.html",
          "name" : "RHSA-2006:0179",
          "refsource" : "REDHAT",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.rudedog.org/auth_ldap/Changes.html",
          "name" : "http://www.rudedog.org/auth_ldap/Changes.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/421286/100/0/threaded",
          "name" : "20060109 Digital Armaments Security Advisory 01.09.2006: Apache auth_ldap module Multiple Format Strings Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16177",
          "name" : "16177",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0117",
          "name" : "ADV-2006-0117",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://wwwnew.mandriva.com/security/advisories?name=MDKSA-2006:017",
          "name" : "MDKSA-2006:017",
          "refsource" : "MANDRIVA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24030",
          "name" : "apache-authldap-format-string(24030)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple format string vulnerabilities in the auth_ldap_log_reason function in Apache auth_ldap 1.6.0 and earlier allows remote attackers to execute arbitrary code via various vectors, including the username."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:dave_carrigan:auth_ldap:1.2.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:dave_carrigan:auth_ldap:1.2.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:dave_carrigan:auth_ldap:1.2.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:dave_carrigan:auth_ldap:1.2.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:dave_carrigan:auth_ldap:1.3.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:dave_carrigan:auth_ldap:1.3.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:dave_carrigan:auth_ldap:1.3.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:dave_carrigan:auth_ldap:1.3.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:dave_carrigan:auth_ldap:1.3.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:dave_carrigan:auth_ldap:1.4.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:dave_carrigan:auth_ldap:1.4.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:dave_carrigan:auth_ldap:1.4.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:dave_carrigan:auth_ldap:1.6.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-09T23:03Z",
    "lastModifiedDate" : "2018-10-19T15:42Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0151",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "todd_miller",
            "product" : {
              "product_data" : [ {
                "product_name" : "sudo",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.5.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.6.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.6.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.6.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.6.3_p1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.6.3_p2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.6.3_p3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.6.3_p4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.6.3_p5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.6.3_p6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.6.3_p7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.6.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.6.4_p1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.6.4_p2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.6.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.6.5_p1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.6.5_p2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.6.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.6.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.6.7_p5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.6.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.6.8_p1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.6.8_p2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.6.8_p5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.6.8_p7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.6.8_p8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.6.8_p9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.6.8_p12",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "ubuntu",
            "product" : {
              "product_data" : [ {
                "product_name" : "ubuntu_linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.04",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.10",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18358",
          "name" : "18358",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18363",
          "name" : "18363",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18549",
          "name" : "18549",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18558",
          "name" : "18558",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18906",
          "name" : "18906",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/19016",
          "name" : "19016",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/21692",
          "name" : "21692",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://slackware.com/security/viewer.php?l=slackware-security&y=2006&m=slackware-security.421822",
          "name" : "SSA:2006-045-08",
          "refsource" : "SLACKWARE",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2006/dsa-946",
          "name" : "DSA-946",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDKSA-2006:159",
          "name" : "MDKSA-2006:159",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.novell.com/linux/security/advisories/2006_02_sr.html",
          "name" : "SUSE-SR:2006:002",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16184",
          "name" : "16184",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.trustix.org/errata/2006/0010",
          "name" : "2006-0010",
          "refsource" : "TRUSTIX",
          "tags" : [ ]
        }, {
          "url" : "https://usn.ubuntu.com/235-2/",
          "name" : "USN-235-2",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "sudo 1.6.8 and other versions does not clear the PYTHONINSPECT environment variable, which allows limited local users to gain privileges via a Python script, a variant of CVE-2005-4158."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:todd_miller:sudo:1.5.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:todd_miller:sudo:1.5.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:todd_miller:sudo:1.5.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:todd_miller:sudo:1.5.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:todd_miller:sudo:1.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:todd_miller:sudo:1.6.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:todd_miller:sudo:1.6.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:todd_miller:sudo:1.6.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:todd_miller:sudo:1.6.3_p1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:todd_miller:sudo:1.6.3_p2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:todd_miller:sudo:1.6.3_p3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:todd_miller:sudo:1.6.3_p4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:todd_miller:sudo:1.6.3_p5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:todd_miller:sudo:1.6.3_p6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:todd_miller:sudo:1.6.3_p7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:todd_miller:sudo:1.6.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:todd_miller:sudo:1.6.4_p1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:todd_miller:sudo:1.6.4_p2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:todd_miller:sudo:1.6.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:todd_miller:sudo:1.6.5_p1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:todd_miller:sudo:1.6.5_p2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:todd_miller:sudo:1.6.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:todd_miller:sudo:1.6.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:todd_miller:sudo:1.6.7_p5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:todd_miller:sudo:1.6.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:todd_miller:sudo:1.6.8_p1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:todd_miller:sudo:1.6.8_p2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:todd_miller:sudo:1.6.8_p5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:todd_miller:sudo:1.6.8_p7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:todd_miller:sudo:1.6.8_p8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:todd_miller:sudo:1.6.8_p9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:todd_miller:sudo:1.6.8_p12:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:ubuntu:ubuntu_linux:4.1:*:ia64:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:ubuntu:ubuntu_linux:4.1:*:ppc:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:ubuntu:ubuntu_linux:5.04:*:amd64:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:ubuntu:ubuntu_linux:5.04:*:i386:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:ubuntu:ubuntu_linux:5.04:*:powerpc:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:ubuntu:ubuntu_linux:5.10:*:amd64:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:ubuntu:ubuntu_linux:5.10:*:i386:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:ubuntu:ubuntu_linux:5.10:*:powerpc:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.2
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 3.9,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-09T23:03Z",
    "lastModifiedDate" : "2018-10-03T21:34Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0152",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "phpchamber",
            "product" : {
              "product_data" : [ {
                "product_name" : "phpchamber",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.2",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18360",
          "name" : "18360",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/22282",
          "name" : "22282",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16180",
          "name" : "16180",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0094",
          "name" : "ADV-2006-0094",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24029",
          "name" : "phpchamber-searchresult-xss(24029)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) in search_result.php in phpChamber 1.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the needle parameter.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:phpchamber:phpchamber:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.2"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-10T11:03Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0153",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "427bb",
            "product" : {
              "product_data" : [ {
                "product_name" : "fourtwosevenbb",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://evuln.com/vulns/18/summary.html",
          "name" : "http://evuln.com/vulns/18/summary.html",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18354",
          "name" : "18354",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/22274",
          "name" : "22274",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/421326/100/0/threaded",
          "name" : "20060107 [eVuln] 427BB Multiple Vulnerabilities (Cookie-based Authentication Bypass, SQL Injections, XSS)",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16178",
          "name" : "16178",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0091",
          "name" : "ADV-2006-0091",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24038",
          "name" : "427bb-scripts-security-bypass(24038)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "427BB 2.2 and 2.2.1 verifies authentication credentials based on the username, authenticated, and usertype cookies, which allows remote attackers to bypass authentication by using a valid username and usertype and setting the authenticated cookie."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:427bb:fourtwosevenbb:2.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:427bb:fourtwosevenbb:2.2.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-10T11:03Z",
    "lastModifiedDate" : "2018-10-19T15:42Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0154",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "427bb",
            "product" : {
              "product_data" : [ {
                "product_name" : "fourtwosevenbb",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://evuln.com/vulns/18/summary.html",
          "name" : "http://evuln.com/vulns/18/summary.html",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18354",
          "name" : "18354",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/22275",
          "name" : "22275",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/421326/100/0/threaded",
          "name" : "20060107 [eVuln] 427BB Multiple Vulnerabilities (Cookie-based Authentication Bypass, SQL Injections, XSS)",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16169",
          "name" : "16169",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0091",
          "name" : "ADV-2006-0091",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24039",
          "name" : "427bb-showthread-sql-injection(24039)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in showthread.php in 427BB 2.2 and 2.2.1 allows remote attackers to execute arbitrary SQL commands via the ForumID parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:427bb:fourtwosevenbb:2.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:427bb:fourtwosevenbb:2.2.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-10T11:03Z",
    "lastModifiedDate" : "2018-10-19T15:42Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0155",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "427bb",
            "product" : {
              "product_data" : [ {
                "product_name" : "fourtwosevenbb",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://evuln.com/vulns/18/summary.html",
          "name" : "http://evuln.com/vulns/18/summary.html",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://secunia.com/advisories/18354",
          "name" : "18354",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/22276",
          "name" : "22276",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/421326/100/0/threaded",
          "name" : "20060107 [eVuln] 427BB Multiple Vulnerabilities (Cookie-based Authentication Bypass, SQL Injections, XSS)",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0091",
          "name" : "ADV-2006-0091",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24040",
          "name" : "427bb-posts-xss(24040)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in posts.php in 427BB 2.2 and 2.2.1 allows remote attackers to inject arbitrary Javascript via a new message with a url bbcode tag containing a javascript URI."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:427bb:fourtwosevenbb:2.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:427bb:fourtwosevenbb:2.2.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-10T11:03Z",
    "lastModifiedDate" : "2018-10-19T15:42Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0156",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "foxrum",
            "product" : {
              "product_data" : [ {
                "product_name" : "foxrum",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.0.4f",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://evuln.com/vulns/20",
          "name" : "http://evuln.com/vulns/20",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18386",
          "name" : "18386",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/325",
          "name" : "325",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/421277/100/0/threaded",
          "name" : "20060109 [eVuln] Foxrum BBCode XSS Vulnerabilty",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16172",
          "name" : "16172",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0121",
          "name" : "ADV-2006-0121",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24043",
          "name" : "foxrum-bbcode-xss(24043)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in Foxrum 4.0.4f allows remote attackers to inject arbitrary Javascript via the javascript URI in bbcode url tags in (1) addpost1.php and (2) addtopic1.php."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:foxrum:foxrum:4.0.4f:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-10T11:03Z",
    "lastModifiedDate" : "2018-10-19T15:43Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0157",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "reamday_enterprises",
            "product" : {
              "product_data" : [ {
                "product_name" : "magic_news_plus",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0.3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://downloads.securityfocus.com/vulnerabilities/exploits/MagicNewsPlus-pw-change.pl",
          "name" : "http://downloads.securityfocus.com/vulnerabilities/exploits/MagicNewsPlus-pw-change.pl",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://secunia.com/advisories/18601",
          "name" : "18601",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16182",
          "name" : "16182",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "settings.php in Reamday Enterprises Magic News Plus 1.0.3 allows remote attackers to change the administrator password via a change action that specifies identical values for the passwd and admin_password parameters, then declares the new password string in the new_passwd and confirm_passwd parameters."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:reamday_enterprises:magic_news_plus:1.0.3:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-10T11:03Z",
    "lastModifiedDate" : "2008-09-05T20:58Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0158",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "cyberdoc",
            "product" : {
              "product_data" : [ {
                "product_name" : "sitesuite_cms",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/ref/22/22205-sitesuite.txt",
          "name" : "http://osvdb.org/ref/22/22205-sitesuite.txt",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://secunia.com/advisories/18305",
          "name" : "18305",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/22205",
          "name" : "22205",
          "refsource" : "OSVDB",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0038",
          "name" : "ADV-2006-0038",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in index.php in CyberDoc SiteSuite CMS allows remote attackers to execute arbitrary SQL commands via the page parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cyberdoc:sitesuite_cms:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-10T11:03Z",
    "lastModifiedDate" : "2011-03-08T02:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0159",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "javier_suarez_sanz",
            "product" : {
              "product_data" : [ {
                "product_name" : "foro_domus",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.10",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18327",
          "name" : "18327",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/22264",
          "name" : "22264",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0073",
          "name" : "ADV-2006-0073",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24017",
          "name" : "domus-escribir-sql-injection(24017)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in escribir.php in Foro Domus 2.10 allows remote attackers to execute arbitrary SQL commands via the email parameter.  NOTE: the provenance of this information is unknown, although it may be based on post-disclosure analysis of CVE-2006-0110; the details are obtained solely from third party information."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:javier_suarez_sanz:foro_domus:2.10:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-10T11:03Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0160",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "venom_board",
            "product" : {
              "product_data" : [ {
                "product_name" : "venom_board",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.22",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://evuln.com/vulns/21/summary.html",
          "name" : "http://evuln.com/vulns/21/summary.html",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://marc.info/?l=bugtraq&m=113683807903915&w=2",
          "name" : "20060109 [eVuln] Venom Board SQL Injection Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18383",
          "name" : "18383",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/326",
          "name" : "326",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/22297",
          "name" : "22297",
          "refsource" : "OSVDB",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16176",
          "name" : "16176",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0122",
          "name" : "ADV-2006-0122",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24046",
          "name" : "venomboard-addpost-sql-injection(24046)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in add_post.php3 in Venom Board 1.22 allows remote attackers to execute arbitrary SQL commands via the (1) parent, (2) root, and (3) topic_id parameters to post.php3."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:venom_board:venom_board:1.22:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-10T11:03Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0161",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "sun",
            "product" : {
              "product_data" : [ {
                "product_name" : "solaris",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "sunos",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.8",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18371",
          "name" : "18371",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/19087",
          "name" : "19087",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1015455",
          "name" : "1015455",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://sunsolve.sun.com/search/document.do?assetkey=1-26-101933-1",
          "name" : "101933",
          "refsource" : "SUNALERT",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://support.avaya.com/elmodocs2/security/ASA-2006-056.htm",
          "name" : "http://support.avaya.com/elmodocs2/security/ASA-2006-056.htm",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0113",
          "name" : "ADV-2006-0113",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1534",
          "name" : "oval:org.mitre.oval:def:1534",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in uucp in Sun Solaris 8 and 9 has unknown impact and attack vectors.  NOTE: due to the vagueness of the vendor advisory, it is not clear whether this is related to CVE-2004-0780."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:sun:solaris:9.0:*:sparc:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:sun:sunos:5.8:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 4.6
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 3.9,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-10T19:03Z",
    "lastModifiedDate" : "2018-10-30T16:25Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0162",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "clam_anti-virus",
            "product" : {
              "product_data" : [ {
                "product_name" : "clamav",
                "version" : {
                  "version_data" : [ {
                    "version_value" : ".",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.51",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.52",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.53",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.54",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.60",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.65",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.67",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.68",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.68.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.70",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.75.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.80",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.80_rc1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.80_rc2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.80_rc3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.80_rc4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.81",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.82",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.83",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.84",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.84_rc1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.84_rc2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.85",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.85.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.86",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.86.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.86.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.87",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.87.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.grok.org.uk/pipermail/full-disclosure/2006-January/041325.html",
          "name" : "20060112 ZDI-06-001: Clam AntiVirus UPX Unpacking Code Execution Vulnerability",
          "refsource" : "FULLDISC",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18379",
          "name" : "18379",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18453",
          "name" : "18453",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18463",
          "name" : "18463",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18478",
          "name" : "18478",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18548",
          "name" : "18548",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/342",
          "name" : "342",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1015457",
          "name" : "1015457",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.clamav.net/doc/0.88/ChangeLog",
          "name" : "http://www.clamav.net/doc/0.88/ChangeLog",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2006/dsa-947",
          "name" : "DSA-947",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.gentoo.org/security/en/glsa/glsa-200601-07.xml",
          "name" : "GLSA-200601-07",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/385908",
          "name" : "VU#385908",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDKSA-2006:016",
          "name" : "MDKSA-2006:016",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/22318",
          "name" : "22318",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16191",
          "name" : "16191",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.trustix.org/errata/2006/0002/",
          "name" : "2006-0002",
          "refsource" : "TRUSTIX",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0116",
          "name" : "ADV-2006-0116",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.zerodayinitiative.com/advisories/ZDI-06-001.html",
          "name" : "http://www.zerodayinitiative.com/advisories/ZDI-06-001.html",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24047",
          "name" : "clamav-libclamav-upx-bo(24047)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Heap-based buffer overflow in libclamav/upx.c in Clam Antivirus (ClamAV) before 0.88 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted UPX files."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clam_anti-virus:clamav:.:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clam_anti-virus:clamav:0.51:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clam_anti-virus:clamav:0.52:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clam_anti-virus:clamav:0.53:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clam_anti-virus:clamav:0.54:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clam_anti-virus:clamav:0.60:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clam_anti-virus:clamav:0.65:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clam_anti-virus:clamav:0.67:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clam_anti-virus:clamav:0.68:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clam_anti-virus:clamav:0.68.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clam_anti-virus:clamav:0.70:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clam_anti-virus:clamav:0.75.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clam_anti-virus:clamav:0.80:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clam_anti-virus:clamav:0.80_rc1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clam_anti-virus:clamav:0.80_rc2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clam_anti-virus:clamav:0.80_rc3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clam_anti-virus:clamav:0.80_rc4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clam_anti-virus:clamav:0.81:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clam_anti-virus:clamav:0.82:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clam_anti-virus:clamav:0.83:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clam_anti-virus:clamav:0.84:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clam_anti-virus:clamav:0.84_rc1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clam_anti-virus:clamav:0.84_rc2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clam_anti-virus:clamav:0.85:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clam_anti-virus:clamav:0.85.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clam_anti-virus:clamav:0.86:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clam_anti-virus:clamav:0.86.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clam_anti-virus:clamav:0.86.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clam_anti-virus:clamav:0.87:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clam_anti-virus:clamav:0.87.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-10T19:03Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0163",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "francisco_burzi",
            "product" : {
              "product_data" : [ {
                "product_name" : "php-nuke_ev",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.7_r1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lostmon.blogspot.com/2006/01/phpnuke-ev-77-search-module-query.html",
          "name" : "http://lostmon.blogspot.com/2006/01/phpnuke-ev-77-search-module-query.html",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18394",
          "name" : "18394",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/22316",
          "name" : "22316",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16186",
          "name" : "16186",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0120",
          "name" : "ADV-2006-0120",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/44978",
          "name" : "phpnukeev-search-sql-injection(44978)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in the search module (modules/Search/index.php) of PHPNuke EV 7.7 -R1 allows remote attackers to execute arbitrary SQL commands via the query parameter, which is used by the search field.  NOTE: This is a different vulnerability than CVE-2005-3792."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:francisco_burzi:php-nuke_ev:7.7_r1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-11T21:03Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0164",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "woah-projekt",
            "product" : {
              "product_data" : [ {
                "product_name" : "phgstats",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.3.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.4.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.4.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.5",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18346",
          "name" : "18346",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://sourceforge.net/project/shownotes.php?release_id=384232",
          "name" : "http://sourceforge.net/project/shownotes.php?release_id=384232",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.osvdb.org/22302",
          "name" : "22302",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/17469",
          "name" : "17469",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0123",
          "name" : "ADV-2006-0123",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24062",
          "name" : "phgstats-php-file-include(24062)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "phgstats.inc.php in phgstats before 0.5.1, if register_globals is enabled, allows remote attackers to include arbitrary files and execute arbitrary PHP code by modifying the PHGDIR variable."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:woah-projekt:phgstats:0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:woah-projekt:phgstats:0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:woah-projekt:phgstats:0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:woah-projekt:phgstats:0.3.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:woah-projekt:phgstats:0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:woah-projekt:phgstats:0.4.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:woah-projekt:phgstats:0.4.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:woah-projekt:phgstats:0.5:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-11T21:03Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0165",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "plain_black",
            "product" : {
              "product_data" : [ {
                "product_name" : "webgui",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.5.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.2.10_gamma",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.2.11_gamma",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.3.0_beta",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.4.0_beta",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.5.0_beta",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.5.1_beta",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.5.2_beta",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.5.3_beta",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.5.4_gamma",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.5.5_gamma",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.5.6_gamma",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.6.0_beta",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.6.1_beta",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.6.2_gamma",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.6.3_gamma",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.6.4_gamma",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.6.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.7.0_beta",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.7.1_beta",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.7.2_beta",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.7.3_gamma",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.7.4_gamma",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.7.5_gamma",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.7.6_gamma",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.7.7_gamma",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.7.8_gamma",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.8.1_beta",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.8.2_beta",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.8.3_gamma",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18372",
          "name" : "18372",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://sourceforge.net/project/shownotes.php?release_id=384153&group_id=51417",
          "name" : "http://sourceforge.net/project/shownotes.php?release_id=384153&group_id=51417",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://sourceforge.net/tracker/index.php?func=detail&aid=1395371&group_id=51417&atid=463213",
          "name" : "http://sourceforge.net/tracker/index.php?func=detail&aid=1395371&group_id=51417&atid=463213",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0126",
          "name" : "ADV-2006-0126",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24053",
          "name" : "webgui-forms-xss(24053)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in the DataForm Entries functionality in Plain Black WebGUI before 6.8.4 (gamma) allows remote attackers to inject arbitrary Javascript via the (1) url and (2) name field of the default email form."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:plain_black:webgui:5.5.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:plain_black:webgui:6.2.10_gamma:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:plain_black:webgui:6.2.11_gamma:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:plain_black:webgui:6.3.0_beta:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:plain_black:webgui:6.4.0_beta:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:plain_black:webgui:6.5.0_beta:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:plain_black:webgui:6.5.1_beta:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:plain_black:webgui:6.5.2_beta:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:plain_black:webgui:6.5.3_beta:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:plain_black:webgui:6.5.4_gamma:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:plain_black:webgui:6.5.5_gamma:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:plain_black:webgui:6.5.6_gamma:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:plain_black:webgui:6.6.0_beta:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:plain_black:webgui:6.6.1_beta:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:plain_black:webgui:6.6.2_gamma:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:plain_black:webgui:6.6.3_gamma:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:plain_black:webgui:6.6.4_gamma:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:plain_black:webgui:6.6.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:plain_black:webgui:6.7.0_beta:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:plain_black:webgui:6.7.1_beta:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:plain_black:webgui:6.7.2_beta:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:plain_black:webgui:6.7.3_gamma:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:plain_black:webgui:6.7.4_gamma:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:plain_black:webgui:6.7.5_gamma:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:plain_black:webgui:6.7.6_gamma:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:plain_black:webgui:6.7.7_gamma:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:plain_black:webgui:6.7.8_gamma:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:plain_black:webgui:6.8.1_beta:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:plain_black:webgui:6.8.2_beta:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:plain_black:webgui:6.8.3_gamma:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-11T21:03Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0166",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "symantec",
            "product" : {
              "product_data" : [ {
                "product_name" : "norton_system_works",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2005",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2005_premier",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2006",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2006_premier",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18402",
          "name" : "18402",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://securityresponse.symantec.com/avcenter/security/Content/2006.01.10.html",
          "name" : "http://securityresponse.symantec.com/avcenter/security/Content/2006.01.10.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1015462",
          "name" : "1015462",
          "refsource" : "SECTRACK",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0143",
          "name" : "ADV-2006-0143",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24061",
          "name" : "systemworks-nprotect-hidden(24061)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Symantec Norton SystemWorks and SystemWorks Premier 2005 and 2006 stores temporary copies of files in the Norton Protected Recycle Bin NProtect directory, which is hidden from the FindFirst and FindNext Windows APIs and allows remote attackers to hide arbitrary files from virus scanners and other products."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:norton_system_works:2005:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:norton_system_works:2005_premier:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:norton_system_works:2006:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:norton_system_works:2006_premier:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-11T21:03Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0167",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "myphpim",
            "product" : {
              "product_data" : [ {
                "product_name" : "myphpim",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "01.05",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://evuln.com/vulns/22/summary.html",
          "name" : "http://evuln.com/vulns/22/summary.html",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18399",
          "name" : "18399",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/22324",
          "name" : "22324",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/22325",
          "name" : "22325",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/421863/100/0/threaded",
          "name" : "20060111 [eVuln] MyPhPim Multiple SQL Injection and XSS Vulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16210",
          "name" : "16210",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0147",
          "name" : "ADV-2006-0147",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24066",
          "name" : "myphpim-calendar-sql-injection(24066)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24075",
          "name" : "myphpim-login-sql-injection(24075)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in MyPhPim 01.05 allows remote attackers to execute arbitrary SQL commands via the (1) cal_id parameter in calendar.php3 and the (2) password field on the login page."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:myphpim:myphpim:01.05:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-11T21:03Z",
    "lastModifiedDate" : "2018-10-19T15:43Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0168",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "myphpim",
            "product" : {
              "product_data" : [ {
                "product_name" : "myphpim",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "01.05",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://evuln.com/vulns/22/summary.html",
          "name" : "http://evuln.com/vulns/22/summary.html",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18399",
          "name" : "18399",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/22326",
          "name" : "22326",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/421863/100/0/threaded",
          "name" : "20060111 [eVuln] MyPhPim Multiple SQL Injection and XSS Vulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16210",
          "name" : "16210",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0147",
          "name" : "ADV-2006-0147",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24071",
          "name" : "myphpim-todo-xss(24071)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in MyPhPim 01.05 allows remote attackers to inject arbitrary web script or HTML via the description field on the \"Create New todo\" page."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:myphpim:myphpim:01.05:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-11T21:03Z",
    "lastModifiedDate" : "2018-10-19T15:43Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0169",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "myphpim",
            "product" : {
              "product_data" : [ {
                "product_name" : "myphpim",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "01.05",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://evuln.com/vulns/23/summary.html",
          "name" : "http://evuln.com/vulns/23/summary.html",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://secunia.com/advisories/18399",
          "name" : "18399",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/421626/100/0/threaded",
          "name" : "20060111 [eVuln] MyPhPim Arbitrary File Upload",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16208",
          "name" : "16208",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0147",
          "name" : "ADV-2006-0147",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24070",
          "name" : "myphpim-addresses-file-upload(24070)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "addresses.php3 in MyPhPim 01.05 does not restrict uploaded files, which allows remote attackers to execute arbitrary PHP code via the pdbfile variable, then directly accessing those files from the uploads directory."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:myphpim:myphpim:01.05:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-11T21:03Z",
    "lastModifiedDate" : "2018-10-19T15:43Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0170",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ ]
        } ]
      },
      "references" : {
        "reference_data" : [ ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2006-0035.  Reason: This candidate is a duplicate of CVE-2006-0035.  Notes: All CVE users should reference CVE-2006-0035 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ ]
    },
    "impact" : { },
    "publishedDate" : "2006-01-11T21:03Z",
    "lastModifiedDate" : "2008-09-10T19:56Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0171",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "orjinweb",
            "product" : {
              "product_data" : [ {
                "product_name" : "orjinweb_e-commerce",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.osvdb.org/22387",
          "name" : "22387",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/421312/100/0/threaded",
          "name" : "20060106 Orjinweb E-commerce",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16199",
          "name" : "16199",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24097",
          "name" : "orjinweb-url-file-include(24097)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "PHP remote file include vulnerability in index.php in OrjinWeb E-commerce allows remote attackers to execute arbitrary code via a URL in the page parameter.  NOTE: it is not clear, but OrjinWeb might be an application service, in which case it should not be included in CVE."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:orjinweb:orjinweb_e-commerce:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-11T21:03Z",
    "lastModifiedDate" : "2018-10-19T15:43Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0172",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "hummingbird",
            "product" : {
              "product_data" : [ {
                "product_name" : "enterprise_collaboration",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.21",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18411",
          "name" : "18411",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securenetwork.it/advisories/sn-2006-01.html",
          "name" : "http://www.securenetwork.it/advisories/sn-2006-01.html",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/421392/100/0/threaded",
          "name" : "20060110 Multiple Vulnerabilities in Hummingbird Collaboration",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16195",
          "name" : "16195",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0145",
          "name" : "ADV-2006-0145",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24067",
          "name" : "hummingbird-enterprise-xss(24067)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in the file manager utility in Hummingbird Collaboration (aka Hummingbird Enterprise Collaboration) 5.21 and earlier allows remote attackers to inject arbitrary web script or HTML in an uploaded page, which is published without a check for hostile scripting."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hummingbird:enterprise_collaboration:5.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hummingbird:enterprise_collaboration:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "5.21"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:S/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 3.5
        },
        "severity" : "LOW",
        "exploitabilityScore" : 6.8,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-11T21:03Z",
    "lastModifiedDate" : "2018-10-19T15:43Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0173",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "hummingbird",
            "product" : {
              "product_data" : [ {
                "product_name" : "enterprise_collaboration",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.21",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18411",
          "name" : "18411",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securenetwork.it/advisories/sn-2006-01.html",
          "name" : "http://www.securenetwork.it/advisories/sn-2006-01.html",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/421392/100/0/threaded",
          "name" : "20060110 Multiple Vulnerabilities in Hummingbird Collaboration",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16195",
          "name" : "16195",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0145",
          "name" : "ADV-2006-0145",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24068",
          "name" : "hummingbird-enterprise-file-download(24068)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Hummingbird Collaboration (aka Hummingbird Enterprise Collaboration) 5.21 and earlier allows remote attackers to misrepresent the type and name of a file via modified doc_ext and id parameters, which might trick a user into downloading dangerous or unexpected content."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hummingbird:enterprise_collaboration:5.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hummingbird:enterprise_collaboration:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "5.21"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-11T21:03Z",
    "lastModifiedDate" : "2018-10-19T15:43Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0174",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "hummingbird",
            "product" : {
              "product_data" : [ {
                "product_name" : "collaboration",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.21",
                    "version_affected" : "<="
                  } ]
                }
              }, {
                "product_name" : "enterprise_collaboration",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.21",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18411",
          "name" : "18411",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/328",
          "name" : "328",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securenetwork.it/advisories/sn-2006-01.html",
          "name" : "http://www.securenetwork.it/advisories/sn-2006-01.html",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/421392/100/0/threaded",
          "name" : "20060110 Multiple Vulnerabilities in Hummingbird Collaboration",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16195",
          "name" : "16195",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0145",
          "name" : "ADV-2006-0145",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24069",
          "name" : "hummingbird-enterprise-information-disclosure(24069)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Hummingbird Collaboration (aka Hummingbird Enterprise Collaboration) 5.21 and earlier allows remote attackers to obtain sensitive information (intranet IP addresses and enumerations of valid parameter values) via a direct request to hc, which reveals the information in an error message or a cookie."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hummingbird:collaboration:5.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hummingbird:collaboration:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "5.21"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hummingbird:enterprise_collaboration:5.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hummingbird:enterprise_collaboration:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "5.21"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-11T21:03Z",
    "lastModifiedDate" : "2018-10-19T15:43Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0175",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "webwiz",
            "product" : {
              "product_data" : [ {
                "product_name" : "web_wiz_forums",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.34",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://archives.neohapsis.com/archives/fulldisclosure/2006-01/0299.html",
          "name" : "20060109 Advisory:XSS vulnerability on WebWiz Forums <= 6.34 (search_form.asp)",
          "refsource" : "FULLDISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.osvdb.org/22398",
          "name" : "22398",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/421615/100/0/threaded",
          "name" : "20060111 Advisory:XSS vulnerability on WebWiz Forums <= 6.34(search_form.asp)",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16196",
          "name" : "16196",
          "refsource" : "BID",
          "tags" : [ "Exploit", "Patch" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24048",
          "name" : "webwizforums-searchform-xss(24048)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in search_form.asp in Web Wiz Forums 6.34 allows remote attackers to inject arbitrary web script or HTML via the search parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:webwiz:web_wiz_forums:6.34:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-11T21:03Z",
    "lastModifiedDate" : "2018-10-19T15:43Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0176",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "xmame",
            "product" : {
              "product_data" : [ {
                "product_name" : "xmame",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.102",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://archives.neohapsis.com/archives/fulldisclosure/2006-01/0353.html",
          "name" : "20060110 mysec.org Security Advisory : Xmame buffer overflow, with a possibility of privilege escalation.",
          "refsource" : "FULLDISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/421849/100/0/threaded",
          "name" : "20060110 mysec.org Security Advisory : Xmame buffer overflow, with a possibility of privilege escalation",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16203",
          "name" : "16203",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://x.mame.net/changes-unix.html",
          "name" : "http://x.mame.net/changes-unix.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24102",
          "name" : "xmame-multiple-parameters-bo(24102)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Buffer overflow in certain functions in src/fileio.c and src/unix/fileio.c in xmame before 11 January 2006 may allow local users to gain privileges via a long (1) -lang, (2) -ctrlr, (3) -pb, or (4) -rec argument on many operating systems, and via a long (5) -jdev argument on Ubuntu Linux."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:xmame:xmame:0.102:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.2
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 3.9,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-11T21:03Z",
    "lastModifiedDate" : "2018-10-19T15:43Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0177",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "cray",
            "product" : {
              "product_data" : [ {
                "product_name" : "unicos",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9.0.2.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://archives.neohapsis.com/archives/fulldisclosure/2006-01/0343.html",
          "name" : "20060110 SUID root overflows in UNICOS and partial shellcode",
          "refsource" : "FULLDISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16205",
          "name" : "16205",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24276",
          "name" : "unicos-command-line-bo(24276)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple buffer overflows in Cray UNICOS 9.0.2.2 might allow local users to gain privileges by (1) invoking /usr/bin/script with a long command line argument or (2) setting the -c option of /etc/nu to the name of a file containing a long line."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cray:unicos:9.0.2.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.2
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 3.9,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-11T21:03Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0178",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "cray",
            "product" : {
              "product_data" : [ {
                "product_name" : "unicos",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9.0.2.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://archives.neohapsis.com/archives/fulldisclosure/2006-01/0343.html",
          "name" : "20060110 SUID root overflows in UNICOS and partial shellcode",
          "refsource" : "FULLDISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16205",
          "name" : "16205",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24277",
          "name" : "unicos-ftp-format-string(24277)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Format string vulnerability in /bin/ftp in UNICOS 9.0.2.2 allows local users to have an unknown impact via format string specifiers in the quote command.  NOTE: because the program is not setuid and not normally called from remote programs, there may not be a typical attack vector for the issue that crosses privilege boundaries. Therefore this may not be a vulnerability."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cray:unicos:9.0.2.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.2
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 3.9,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-11T21:03Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0179",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "cisco",
            "product" : {
              "product_data" : [ {
                "product_name" : "ip_phone_7940",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://downloads.securityfocus.com/vulnerabilities/exploits/cisco_ip7940_dos.pl",
          "name" : "http://downloads.securityfocus.com/vulnerabilities/exploits/cisco_ip7940_dos.pl",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://secunia.com/advisories/18479",
          "name" : "18479",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1015488",
          "name" : "1015488",
          "refsource" : "SECTRACK",
          "tags" : [ "Exploit", "Patch" ]
        }, {
          "url" : "http://www.cisco.com/warp/public/707/cisco-response-20060113-ip-phones.shtml",
          "name" : "20060113 Response to Cisco IP Phone 7940 DoS Exploit posted on milw0rm.com",
          "refsource" : "CISCO",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/22469",
          "name" : "22469",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16200",
          "name" : "16200",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0202",
          "name" : "ADV-2006-0202",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24117",
          "name" : "cisco-ipphone-synflood-dos(24117)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/1411",
          "name" : "1411",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The Cisco IP Phone 7940 allows remote attackers to cause a denial of service (reboot) via a large amount of TCP SYN packets (syn flood) to arbitrary ports, as demonstrated to port 80."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:ip_phone_7940:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-11T21:03Z",
    "lastModifiedDate" : "2017-10-19T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0180",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "calogic",
            "product" : {
              "product_data" : [ {
                "product_name" : "calogic_calendars",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.2.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://evuln.com/vulns/24/summary.html",
          "name" : "http://evuln.com/vulns/24/summary.html",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18417",
          "name" : "18417",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/22322",
          "name" : "22322",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/422163/100/0/threaded",
          "name" : "20060116 [eVuln] CaLogic Calendars Multiple XSS Vulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16206",
          "name" : "16206",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0149",
          "name" : "ADV-2006-0149",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24077",
          "name" : "calogic-newevent-xss(24077)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in CaLogic Calendars 1.2.2 allows remote attackers to inject arbitrary web script or HTML via the Title field on the \"Adding New Event\" page, and possibly other vectors, involving iframe tags."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:calogic:calogic_calendars:1.2.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-12T06:02Z",
    "lastModifiedDate" : "2018-10-19T15:43Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0181",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "cisco",
            "product" : {
              "product_data" : [ {
                "product_name" : "cs-mars",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://seclists.org/bugtraq/2006/Jan/202",
          "name" : "20060112 Cisco, haven't we learned anything? (technician reset)",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18424",
          "name" : "18424",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/335",
          "name" : "335",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1015471",
          "name" : "1015471",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.cisco.com/warp/public/707/cisco-sa-20060111-mars.shtml",
          "name" : "20060111 Default Administrative Password in Cisco Security Monitoring, Analysis and Response System (CS-MARS)",
          "refsource" : "CISCO",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/22346",
          "name" : "22346",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16211",
          "name" : "16211",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0154",
          "name" : "ADV-2006-0154",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24065",
          "name" : "cisco-csmars-default-password(24065)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cisco Security Monitoring, Analysis and Response System (CS-MARS) before 4.1.3 has an undocumented administrative account with a default password, which allows local users to gain privileges via the expert command."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:cs-mars:4.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:cs-mars:4.1.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.2
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 3.9,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-12T06:02Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0182",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "acal",
            "product" : {
              "product_data" : [ {
                "product_name" : "calendar_project",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.2.5",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://evuln.com/vulns/25/summary.html",
          "name" : "http://evuln.com/vulns/25/summary.html",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18432",
          "name" : "18432",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/343",
          "name" : "343",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/22344",
          "name" : "22344",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/421744/100/0/threaded",
          "name" : "20060112 [eVuln] ACal Authentication Bypass & PHP Code Insertion",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0152",
          "name" : "ADV-2006-0152",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24104",
          "name" : "acal-login-auth-bypass(24104)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "login.php in ACal Calendar Project 2.2.5 allows remote attackers to bypass authentication by setting the ACalAuthenticate cookie variable to \"inside\"."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:acal:calendar_project:2.2.5:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-12T06:02Z",
    "lastModifiedDate" : "2018-10-19T15:43Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0183",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "acal",
            "product" : {
              "product_data" : [ {
                "product_name" : "calendar_project",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.2.5",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://evuln.com/vulns/25/summary.html",
          "name" : "http://evuln.com/vulns/25/summary.html",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18432",
          "name" : "18432",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/343",
          "name" : "343",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/22345",
          "name" : "22345",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/421744/100/0/threaded",
          "name" : "20060112 [eVuln] ACal Authentication Bypass & PHP Code Insertion",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0152",
          "name" : "ADV-2006-0152",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24107",
          "name" : "acal-header-footer-code-execute(24107)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Direct static code injection vulnerability in edit.php in ACal Calendar Project 2.2.5 allows authenticated users to execute arbitrary PHP code via (1) the edit=header value, which modifies header.php, or (2) the edit=footer value, which modifies footer.php.  NOTE: this issue might be resultant from the poor authentication as identified by CVE-2006-0182.  Since the design of the product allows the administrator to edit the code, perhaps this issue should not be included in CVE, except as a consequence of CVE-2006-0182."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:acal:calendar_project:2.2.5:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.5
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-12T06:02Z",
    "lastModifiedDate" : "2018-10-19T15:43Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0184",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "mainenet_enterprises",
            "product" : {
              "product_data" : [ {
                "product_name" : "asptopsites",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://archives.neohapsis.com/archives/fulldisclosure/2006-01/0351.html",
          "name" : "20060110 AspTopSites SQL injection",
          "refsource" : "FULLDISC",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18408",
          "name" : "18408",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.exploitlabs.com/files/advisories/EXPL-A-2006-001-asptopsites.txt",
          "name" : "http://www.exploitlabs.com/files/advisories/EXPL-A-2006-001-asptopsites.txt",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/22330",
          "name" : "22330",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0146",
          "name" : "ADV-2006-0146",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24072",
          "name" : "asptopsites-goto-sql-injection(24072)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple SQL injection vulnerabilities in AspTopSites allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to goto.asp or (2) password parameter to includeloginuser.asp."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mainenet_enterprises:asptopsites:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-12T06:02Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0185",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "php-nuke",
            "product" : {
              "product_data" : [ {
                "product_name" : "news_module",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "pool_module",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18374",
          "name" : "18374",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/421322",
          "name" : "20060107 Php-Nuke Pool and News Module IMG Tag Cross Site",
          "refsource" : "BUGTRAQ",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16192",
          "name" : "16192",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0125",
          "name" : "ADV-2006-0125",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple cross-site scripting vulnerabilities in the (1) Pool or (2) News Modules in Php-Nuke allow remote attackers to inject arbitrary web script or HTML via javascript in the SRC attribute of an IMG tag."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php-nuke:news_module:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php-nuke:pool_module:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-12T06:02Z",
    "lastModifiedDate" : "2011-03-08T02:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0186",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ ]
        } ]
      },
      "references" : {
        "reference_data" : [ ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2005-4500.  Reason: This candidate is a duplicate of CVE-2005-4500.  Notes: All CVE users should reference CVE-2005-4500 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ ]
    },
    "impact" : { },
    "publishedDate" : "2006-01-12T06:02Z",
    "lastModifiedDate" : "2008-09-10T19:56Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0187",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "visual_studio_.net",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2005",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18409",
          "name" : "18409",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/421943/100/0/threaded",
          "name" : "20060113 Visual Studio Remote Code Execution",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16225",
          "name" : "16225",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0151",
          "name" : "ADV-2006-0151",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24116",
          "name" : "visualstudio-usercontrol-code-execution(24116)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "By design, Microsoft Visual Studio 2005 automatically executes code in the Load event of a user-defined control (UserControl1_Load function), which allows user-assisted attackers to execute arbitrary code by tricking the user into opening a malicious Visual Studio project file."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:visual_studio_.net:2005:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:H/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "HIGH",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.1
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 4.9,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2006-01-12T06:02Z",
    "lastModifiedDate" : "2018-10-19T15:43Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0188",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "squirrelmail",
            "product" : {
              "product_data" : [ {
                "product_name" : "squirrelmail",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.3_r3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.3_rc1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.3a",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.4_rc1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.6_rc1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4_rc1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "ftp://patches.sgi.com/support/free/security/advisories/20060501-01-U.asc",
          "name" : "20060501-01-U",
          "refsource" : "SGI",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18985",
          "name" : "18985",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/19130",
          "name" : "19130",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/19131",
          "name" : "19131",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/19176",
          "name" : "19176",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/19205",
          "name" : "19205",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/19960",
          "name" : "19960",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/20210",
          "name" : "20210",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1015662",
          "name" : "1015662",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2006/dsa-988",
          "name" : "DSA-988",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.gentoo.org/security/en/glsa/glsa-200603-09.xml",
          "name" : "GLSA-200603-09",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDKSA-2006:049",
          "name" : "MDKSA-2006:049",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.novell.com/linux/security/advisories/2006_05_sr.html",
          "name" : "SUSE-SR:2006:005",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/archives/fedora-announce-list/2006-March/msg00004.html",
          "name" : "FEDORA-2006-133",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2006-0283.html",
          "name" : "RHSA-2006:0283",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16756",
          "name" : "16756",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.squirrelmail.org/security/issue/2006-02-01",
          "name" : "http://www.squirrelmail.org/security/issue/2006-02-01",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0689",
          "name" : "ADV-2006-0689",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24847",
          "name" : "squirrelmail-webmail-xss(24847)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10419",
          "name" : "oval:org.mitre.oval:def:10419",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "webmail.php in SquirrelMail 1.4.0 to 1.4.5 allows remote attackers to inject arbitrary web pages into the right frame via a URL in the right_frame parameter.  NOTE: this has been called a cross-site scripting (XSS) issue, but it is different than what is normally identified as XSS."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:squirrelmail:squirrelmail:1.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:squirrelmail:squirrelmail:1.4.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:squirrelmail:squirrelmail:1.4.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:squirrelmail:squirrelmail:1.4.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:squirrelmail:squirrelmail:1.4.3_r3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:squirrelmail:squirrelmail:1.4.3_rc1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:squirrelmail:squirrelmail:1.4.3a:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:squirrelmail:squirrelmail:1.4.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:squirrelmail:squirrelmail:1.4.4_rc1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:squirrelmail:squirrelmail:1.4.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:squirrelmail:squirrelmail:1.4.6_rc1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:squirrelmail:squirrelmail:1.4_rc1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-24T00:02Z",
    "lastModifiedDate" : "2017-10-11T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0189",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "estara",
            "product" : {
              "product_data" : [ {
                "product_name" : "softphone",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.0.1.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.1.46",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18410",
          "name" : "18410",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1015481",
          "name" : "1015481",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/22348",
          "name" : "22348",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/421596/100/0/threaded",
          "name" : "20060111 eStara Softphone SIP stack Buffer Overflow Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16213",
          "name" : "16213",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0167",
          "name" : "ADV-2006-0167",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24090",
          "name" : "estara-sip-sdp-bo(24090)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Buffer overflow in eStara Softphone 3.0.1.14 through 3.0.1.46 allows remote attackers to execute arbitrary code via a long attribute (aka \"a\") field in the SDP data of a SIP packet on UDP port 5060."
        }, {
          "lang" : "en",
          "value" : "This is the vendor provided solution:\r\n\r\n\"eStara has released Softphone version 3.0.1.47 to resolve the buffer overflow demonstrated in parsing SDP with long \"a=\" lines.  Licensed customers can download a new version via the email sent to them with purchase, customers testing may go back to http://www.estara.com/softphone/ to obtain a new free trial.   Version information can be gathered by going to Help->About.  eStara highly recommends all customers upgrade to avoid this issue.  If there's further questions please email us: softphone@estara.com.\r\n \r\neStara would like to thank ZwelL for bringing the issue to our attention.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:estara:softphone:3.0.1.14:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:estara:softphone:3.0.1.46:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-13T11:03Z",
    "lastModifiedDate" : "2018-10-19T15:43Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0190",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "sun",
            "product" : {
              "product_data" : [ {
                "product_name" : "solaris",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18421",
          "name" : "18421",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/19087",
          "name" : "19087",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1015478",
          "name" : "1015478",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://sunsolve.sun.com/searchproxy/document.do?assetkey=1-26-102066-1",
          "name" : "102066",
          "refsource" : "SUNALERT",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://support.avaya.com/elmodocs2/security/ASA-2006-056.htm",
          "name" : "http://support.avaya.com/elmodocs2/security/ASA-2006-056.htm",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16224",
          "name" : "16224",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0165",
          "name" : "ADV-2006-0165",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24084",
          "name" : "solaris-unspecified-root-access(24084)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A702",
          "name" : "oval:org.mitre.oval:def:702",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in Sun Solaris 9 and 10 for the x86 platform allows local users to gain privileges or cause a denial of service (panic) via unspecified vectors, possibly involving functions from the mm driver."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:sun:solaris:9.0:*:sparc:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:sun:solaris:10.0:*:sparc:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.2
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 3.9,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-13T11:03Z",
    "lastModifiedDate" : "2017-10-11T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0191",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "sun",
            "product" : {
              "product_data" : [ {
                "product_name" : "solaris",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18420",
          "name" : "18420",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/19087",
          "name" : "19087",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1015479",
          "name" : "1015479",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://sunsolve.sun.com/searchproxy/document.do?assetkey=1-26-102108-1",
          "name" : "102108",
          "refsource" : "SUNALERT",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://support.avaya.com/elmodocs2/security/ASA-2006-056.htm",
          "name" : "http://support.avaya.com/elmodocs2/security/ASA-2006-056.htm",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/22347",
          "name" : "22347",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16222",
          "name" : "16222",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0166",
          "name" : "ADV-2006-0166",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24085",
          "name" : "solaris-find-proc-dos(24085)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1608",
          "name" : "oval:org.mitre.oval:def:1608",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in Sun Solaris 10 allows local users to cause a denial of service (null dereference) via unspecified vectors involving the use of the find command on the \"/proc\" filesystem. NOTE: due to the vagueness of the vendor advisory, it is not clear whether this is related to CVE-2005-3250."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:sun:solaris:10.0:*:sparc:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:N/I:N/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 4.9
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 3.9,
        "impactScore" : 6.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-13T11:03Z",
    "lastModifiedDate" : "2017-10-11T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0192",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "philip_loftin",
            "product" : {
              "product_data" : [ {
                "product_name" : "aspsurvey",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.10",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18422",
          "name" : "18422",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/414",
          "name" : "414",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/22342",
          "name" : "22342",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/423949/100/0/threaded",
          "name" : "20060204 sql injection in ASP Survey",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16496",
          "name" : "16496",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0164",
          "name" : "ADV-2006-0164",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24087",
          "name" : "aspsurvey-loginvalidate-sql-injection(24087)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in Login_Validate.asp in ASPSurvey 1.10 allows remote attackers to execute arbitrary SQL commands via the Password parameter to login.asp."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:philip_loftin:aspsurvey:1.10:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-13T11:03Z",
    "lastModifiedDate" : "2018-10-19T15:43Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0193",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "positive_software",
            "product" : {
              "product_data" : [ {
                "product_name" : "h-sphere",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.4.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.4.1_patch_1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.4.1_patch_2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.4.1_patch_3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.4.1_patch_4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.4.1_patch_5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.4.1_patch_6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.4.1_patch_7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.4.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.4.2_beta_1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.4.2_beta_2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.4.2_beta_3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.4.2_patch_1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.4.2_patch_2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.4.2_patch_3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.4.2_patch_4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.4.2_patch_5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.4.2_rc1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.4.2_rc2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.4.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.4.3_beta_1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.4.3_beta_2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.4.3_patch_1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.4.3_patch_2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.4.3_patch_3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.4.3_patch_4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.4.3_patch_5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.4.3_patch_6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.4.3_patch_7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.4.3_patch_8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.4.3_rc1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.4.3_rc2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18447",
          "name" : "18447",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/22372",
          "name" : "22372",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.psoft.net/HSdocumentation/versions/?v=all&p=r",
          "name" : "http://www.psoft.net/HSdocumentation/versions/?v=all&p=r",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.psoft.net/HSdocumentation/versions/index.php?v=243p9&p=r",
          "name" : "http://www.psoft.net/HSdocumentation/versions/index.php?v=243p9&p=r",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/421704/100/0/threaded",
          "name" : "20060112 H-Sphere Security Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0172",
          "name" : "ADV-2006-0172",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24096",
          "name" : "hsphere-login-xss(24096)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in the Hosting Control Panel (psoft.hsphere.CP) in Positive Software H-Sphere 2.4.3 Patch 8 and earlier allows remote attackers to inject arbitrary web script or HTML via the login parameter in a login action."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:positive_software:h-sphere:2.4.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:positive_software:h-sphere:2.4.1_patch_1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:positive_software:h-sphere:2.4.1_patch_2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:positive_software:h-sphere:2.4.1_patch_3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:positive_software:h-sphere:2.4.1_patch_4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:positive_software:h-sphere:2.4.1_patch_5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:positive_software:h-sphere:2.4.1_patch_6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:positive_software:h-sphere:2.4.1_patch_7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:positive_software:h-sphere:2.4.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:positive_software:h-sphere:2.4.2_beta_1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:positive_software:h-sphere:2.4.2_beta_2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:positive_software:h-sphere:2.4.2_beta_3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:positive_software:h-sphere:2.4.2_patch_1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:positive_software:h-sphere:2.4.2_patch_2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:positive_software:h-sphere:2.4.2_patch_3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:positive_software:h-sphere:2.4.2_patch_4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:positive_software:h-sphere:2.4.2_patch_5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:positive_software:h-sphere:2.4.2_rc1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:positive_software:h-sphere:2.4.2_rc2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:positive_software:h-sphere:2.4.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:positive_software:h-sphere:2.4.3_beta_1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:positive_software:h-sphere:2.4.3_beta_2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:positive_software:h-sphere:2.4.3_patch_1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:positive_software:h-sphere:2.4.3_patch_2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:positive_software:h-sphere:2.4.3_patch_3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:positive_software:h-sphere:2.4.3_patch_4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:positive_software:h-sphere:2.4.3_patch_5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:positive_software:h-sphere:2.4.3_patch_6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:positive_software:h-sphere:2.4.3_patch_7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:positive_software:h-sphere:2.4.3_patch_8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:positive_software:h-sphere:2.4.3_rc1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:positive_software:h-sphere:2.4.3_rc2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-13T11:03Z",
    "lastModifiedDate" : "2018-10-19T15:43Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0194",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "fog_creek_software",
            "product" : {
              "product_data" : [ {
                "product_name" : "fogbugz",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.029",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18443",
          "name" : "18443",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.fogcreek.com/FogBugz/KB/releaseNotes/WhatsNewInFogBugz4.0.33.html",
          "name" : "http://www.fogcreek.com/FogBugz/KB/releaseNotes/WhatsNewInFogBugz4.0.33.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/22370",
          "name" : "22370",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/421729/100/0/threaded",
          "name" : "20060112 FogBugz Cross Site Scripting Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16216",
          "name" : "16216",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0174",
          "name" : "ADV-2006-0174",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24103",
          "name" : "fogbugz-login-xss(24103)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in default.asp in FogBugz 4.029, and other versions before 4.0.33, allows remote attackers to inject arbitrary web script or HTML via the dest parameter in the pgLogon page."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:fog_creek_software:fogbugz:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "4.029"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-13T11:03Z",
    "lastModifiedDate" : "2018-10-19T15:43Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0195",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "squirrelmail",
            "product" : {
              "product_data" : [ {
                "product_name" : "squirrelmail",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.3_r3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.3_rc1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.3a",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.4_rc1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.6_rc1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4_rc1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "ftp://patches.sgi.com/support/free/security/advisories/20060501-01-U.asc",
          "name" : "20060501-01-U",
          "refsource" : "SGI",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18985",
          "name" : "18985",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/19130",
          "name" : "19130",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/19131",
          "name" : "19131",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/19176",
          "name" : "19176",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/19205",
          "name" : "19205",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/19960",
          "name" : "19960",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/20210",
          "name" : "20210",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1015662",
          "name" : "1015662",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2006/dsa-988",
          "name" : "DSA-988",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.gentoo.org/security/en/glsa/glsa-200603-09.xml",
          "name" : "GLSA-200603-09",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDKSA-2006:049",
          "name" : "MDKSA-2006:049",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.novell.com/linux/security/advisories/2006_05_sr.html",
          "name" : "SUSE-SR:2006:005",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/archives/fedora-announce-list/2006-March/msg00004.html",
          "name" : "FEDORA-2006-133",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2006-0283.html",
          "name" : "RHSA-2006:0283",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16756",
          "name" : "16756",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.squirrelmail.org/security/issue/2006-02-10",
          "name" : "http://www.squirrelmail.org/security/issue/2006-02-10",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0689",
          "name" : "ADV-2006-0689",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24848",
          "name" : "squirrelmail-magichtml-xss(24848)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9548",
          "name" : "oval:org.mitre.oval:def:9548",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Interpretation conflict in the MagicHTML filter in SquirrelMail 1.4.0 to 1.4.5 allows remote attackers to conduct cross-site scripting (XSS) attacks via style sheet specifiers with invalid (1) \"/*\" and \"*/\" comments, or (2) a newline in a \"url\" specifier, which is processed by certain web browsers including Internet Explorer."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:squirrelmail:squirrelmail:1.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:squirrelmail:squirrelmail:1.4.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:squirrelmail:squirrelmail:1.4.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:squirrelmail:squirrelmail:1.4.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:squirrelmail:squirrelmail:1.4.3_r3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:squirrelmail:squirrelmail:1.4.3_rc1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:squirrelmail:squirrelmail:1.4.3a:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:squirrelmail:squirrelmail:1.4.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:squirrelmail:squirrelmail:1.4.4_rc1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:squirrelmail:squirrelmail:1.4.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:squirrelmail:squirrelmail:1.4.6_rc1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:squirrelmail:squirrelmail:1.4_rc1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-24T00:02Z",
    "lastModifiedDate" : "2017-10-11T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0196",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "serial_line_sniffer",
            "product" : {
              "product_data" : [ {
                "product_name" : "serial_line_sniffer",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.4.4",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18497",
          "name" : "18497",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://shellcoders.com/sintigan/slsnif-ploit.pl",
          "name" : "http://shellcoders.com/sintigan/slsnif-ploit.pl",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/421583/100/0/threaded",
          "name" : "20060111 Serial Line Sniffer 0.4.4 Buffer Overflow",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0212",
          "name" : "ADV-2006-0212",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24082",
          "name" : "slsnif-home-bo(24082)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in Serial line sniffer (aka slsnif) 0.4.4 allows local users to gain privileges via a long value of the HOME environment variable, possibly because of a buffer overflow."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:serial_line_sniffer:serial_line_sniffer:0.4.4:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 4.6
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 3.9,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-13T23:03Z",
    "lastModifiedDate" : "2018-10-19T15:43Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0197",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "x.org",
            "product" : {
              "product_data" : [ {
                "product_name" : "x.org",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.8.2",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/archive/1/421256/100/0/threaded",
          "name" : "20060108 xorg server 6.8.2 and below on 64bit arch",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The XClientMessageEvent struct used in certain components of X.Org 6.8.2 and earlier, possibly including (1) the X server and (2) Xlib, uses a \"long\" specifier for elements of the l array, which results in inconsistent sizes in the struct on 32-bit versus 64-bit platforms, and might allow attackers to cause a denial of service (application crash) and possibly conduct other attacks."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:x.org:x.org:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "6.8.2"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-13T23:03Z",
    "lastModifiedDate" : "2018-10-19T15:43Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0198",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "xoops",
            "product" : {
              "product_data" : [ {
                "product_name" : "xoops_pool_module",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/archive/1/421325/100/0/threaded",
          "name" : "20060107 Xoops Pool Module IMG Tag Cross Site Scripting",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16189",
          "name" : "16189",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.xoops.org/modules/newbb/viewtopic.php?topic_id=45637&forum=2&post_id=200481",
          "name" : "http://www.xoops.org/modules/newbb/viewtopic.php?topic_id=45637&forum=2&post_id=200481",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24091",
          "name" : "xoops-pool-imagetag-xss(24091)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in a certain module, possibly poll or Pool, for XOOPS allows remote attackers to inject arbitrary web script or HTML via JavaScript in the SRC attribute of an IMG element in a comment."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:xoops:xoops_pool_module:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-13T23:03Z",
    "lastModifiedDate" : "2018-10-19T15:43Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0199",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "mini-nuke",
            "product" : {
              "product_data" : [ {
                "product_name" : "cms_system",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.8.2",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://archives.neohapsis.com/archives/fulldisclosure/2006-01/0439.html",
          "name" : "20060112 Advisory: MiniNuke CMS System <= 1.8.2 (news.asp) SQL Injection vulnerability",
          "refsource" : "FULLDISC",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18439",
          "name" : "18439",
          "refsource" : "SECUNIA",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/340",
          "name" : "340",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.nukedx.com/?viewdoc=7",
          "name" : "http://www.nukedx.com/?viewdoc=7",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/22384",
          "name" : "22384",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/421727/100/0/threaded",
          "name" : "20060113 Advisory: MiniNuke CMS System <= 1.8.2 (news.asp) SQL Injectionvulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0173",
          "name" : "ADV-2006-0173",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24098",
          "name" : "mininuke-news-sql-injection(24098)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in news.asp in Mini-Nuke CMS System 1.8.2 and earlier allows remote attackers to execute arbitrary SQL commands via the hid parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mini-nuke:cms_system:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.8.2"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-13T23:03Z",
    "lastModifiedDate" : "2018-10-19T15:43Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0200",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "php",
            "product" : {
              "product_data" : [ {
                "product_name" : "php",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.1.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-134"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18431",
          "name" : "18431",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/337",
          "name" : "337",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1015485",
          "name" : "1015485",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.hardened-php.net/advisory_022006.113.html",
          "name" : "http://www.hardened-php.net/advisory_022006.113.html",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.php.net/release_5_1_2.php",
          "name" : "http://www.php.net/release_5_1_2.php",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/421705/100/0/threaded",
          "name" : "20060112 Advisory 02/2006: PHP ext/mysqli Format String Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16219",
          "name" : "16219",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0177",
          "name" : "ADV-2006-0177",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0369",
          "name" : "ADV-2006-0369",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24095",
          "name" : "php-extmysqli-format-string(24095)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Format string vulnerability in the error-reporting feature in the mysqli extension in PHP 5.1.0 and 5.1.1 might allow remote attackers to execute arbitrary code via format string specifiers in MySQL error messages."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:5.1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:5.1.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-13T23:03Z",
    "lastModifiedDate" : "2018-10-30T16:25Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0201",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "paypal",
            "product" : {
              "product_data" : [ {
                "product_name" : "php_toolkit",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.50",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18444",
          "name" : "18444",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/22378",
          "name" : "22378",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/421739",
          "name" : "20060112 Multiple PHP Toolkit for PayPal Vulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16218",
          "name" : "16218",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.uinc.ru/articles/vuln/ptpaypal050.shtml",
          "name" : "http://www.uinc.ru/articles/vuln/ptpaypal050.shtml",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0183",
          "name" : "ADV-2006-0183",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Dave Nielsen and Patrick Breitenbach PayPal Web Services (aka PHP Toolkit) 0.50, and possibly earlier versions, allows remote attackers to enter false payment entries into the log file via HTTP POST requests to ipn_success.php."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:paypal:php_toolkit:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "0.50"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-13T23:03Z",
    "lastModifiedDate" : "2011-03-08T02:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0202",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "paypal",
            "product" : {
              "product_data" : [ {
                "product_name" : "php_toolkit",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.50",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18444",
          "name" : "18444",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/22379",
          "name" : "22379",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/421739",
          "name" : "20060112 Multiple PHP Toolkit for PayPal Vulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16218",
          "name" : "16218",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.uinc.ru/articles/vuln/ptpaypal050.shtml",
          "name" : "http://www.uinc.ru/articles/vuln/ptpaypal050.shtml",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0183",
          "name" : "ADV-2006-0183",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Dave Nielsen and Patrick Breitenbach PayPal Web Services (aka PHP Toolkit) 0.50 and possibly earlier has (1) world-readable permissions for ipn/logs/ipn_success.txt, which allows local users to view sensitive information (payment data), and (2) world-writable permissions for ipn/logs, which allows local users to delete or replace payment data."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:paypal:php_toolkit:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "0.50"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:P/I:P/A:N",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 3.6
        },
        "severity" : "LOW",
        "exploitabilityScore" : 3.9,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-13T23:03Z",
    "lastModifiedDate" : "2011-03-08T02:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0203",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "mini-nuke",
            "product" : {
              "product_data" : [ {
                "product_name" : "cms_system",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.8.2",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-20"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://archives.neohapsis.com/archives/bugtraq/2006-01/0483.html",
          "name" : "20060129 [xpl#2] MiniNuke 1.8.2 - change member's passwrod < Perl >",
          "refsource" : "BUGTRAQ",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://archives.neohapsis.com/archives/fulldisclosure/2006-01/0437.html",
          "name" : "20060112 Advisory: MiniNuke CMS System <= 1.8.2 (membership.asp) remote user password change exploit",
          "refsource" : "FULLDISC",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://archives.neohapsis.com/archives/fulldisclosure/2006-01/0439.html",
          "name" : "20060112 Advisory: MiniNuke CMS System <= 1.8.2 (news.asp) SQL Injection vulnerability",
          "refsource" : "FULLDISC",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18439",
          "name" : "18439",
          "refsource" : "SECUNIA",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/344",
          "name" : "344",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/22385",
          "name" : "22385",
          "refsource" : "OSVDB",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/421748/100/0/threaded",
          "name" : "20060113 Advisory: MiniNuke CMS System <= 1.8.2 (membership.asp) remoteuser password change exploit",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0173",
          "name" : "ADV-2006-0173",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24101",
          "name" : "mininuke-membership-change-password(24101)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "membership.asp in Mini-Nuke CMS System 1.8.2 and earlier does not verify the old password when changing a password, which allows remote attackers to change the passwords of other members via a lostpassnew action with a modified x parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mini-nuke:cms_system:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.8.2"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-13T23:03Z",
    "lastModifiedDate" : "2018-10-19T15:43Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0204",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "wordcircle",
            "product" : {
              "product_data" : [ {
                "product_name" : "wordcircle",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.17",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://evuln.com/vulns/28/summary.html",
          "name" : "http://evuln.com/vulns/28/summary.html",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18440",
          "name" : "18440",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/345",
          "name" : "345",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/22359",
          "name" : "22359",
          "refsource" : "OSVDB",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/421746/100/0/threaded",
          "name" : "20060112 [eVuln] Wordcircle Multiple SQL Injection & XSS Vulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16227",
          "name" : "16227",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0185",
          "name" : "ADV-2006-0185",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24106",
          "name" : "wordcircle-index-xss(24106)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple cross-site scripting (XSS) vulnerabilities in Wordcircle 2.17 allow remote attackers to inject arbitrary web script or HTML via (1) the \"Course name\" field in index.php when the frm parameter has the value \"mine\" and (2) possibly certain other fields in unspecified scripts."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wordcircle:wordcircle:2.17:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-13T23:03Z",
    "lastModifiedDate" : "2018-10-19T15:43Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0205",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "wordcircle",
            "product" : {
              "product_data" : [ {
                "product_name" : "wordcircle",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.17",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://evuln.com/vulns/27/summary.html",
          "name" : "http://evuln.com/vulns/27/summary.html",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://evuln.com/vulns/28/summary.html",
          "name" : "http://evuln.com/vulns/28/summary.html",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://secunia.com/advisories/18440",
          "name" : "18440",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/345",
          "name" : "345",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/346",
          "name" : "346",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/22358",
          "name" : "22358",
          "refsource" : "OSVDB",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/421745/100/0/threaded",
          "name" : "20060112 [eVuln] Wordcircle Authentication Bypass",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/421746/100/0/threaded",
          "name" : "20060112 [eVuln] Wordcircle Multiple SQL Injection & XSS Vulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16227",
          "name" : "16227",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0185",
          "name" : "ADV-2006-0185",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24105",
          "name" : "wordcircle-sql-injection(24105)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24108",
          "name" : "wordcircle-login-security-bypass(24108)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple SQL injection vulnerabilities in Wordcircle 2.17 allow remote attackers to (1) execute arbitrary SQL commands and bypass authentication via the password field in the login action to index.php (involving v_login.php and s_user.php) and (2) have other unknown impact via certain other fields in unspecified scripts."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wordcircle:wordcircle:2.17:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:H/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "HIGH",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.1
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 4.9,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-13T23:03Z",
    "lastModifiedDate" : "2018-10-19T15:43Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0206",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "light_weight_calendar",
            "product" : {
              "product_data" : [ {
                "product_name" : "light_weight_calendar",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://attrition.org/pipermail/vim/2006-March/000612.html",
          "name" : "20060318 Source VERIFY - Light Weight Calendar issue is eval injection",
          "refsource" : "VIM",
          "tags" : [ ]
        }, {
          "url" : "http://evuln.com/vulns/29/exploit.html",
          "name" : "http://evuln.com/vulns/29/exploit.html",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://evuln.com/vulns/29/summary.html",
          "name" : "http://evuln.com/vulns/29/summary.html",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18450",
          "name" : "18450",
          "refsource" : "SECUNIA",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/22376",
          "name" : "22376",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/421920",
          "name" : "20060113 [eVuln] Light Weight Calendar PHP Code Execution",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16229",
          "name" : "16229",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0171",
          "name" : "ADV-2006-0171",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24110",
          "name" : "lwc-cal-execute-code(24110)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Eval injection vulnerability in Light Weight Calendar (LWC) 1.0 (20040909) and earlier allows remote attackers to execute arbitrary PHP code via the date parameter in cal.php, which is included by index.php."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:light_weight_calendar:light_weight_calendar:1.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-13T23:03Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0207",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "php",
            "product" : {
              "product_data" : [ {
                "product_name" : "php",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.1.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-94"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.suse.de/archive/suse-security-announce/2006-Feb/0008.html",
          "name" : "SUSE-SR:2006:004",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18431",
          "name" : "18431",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18697",
          "name" : "18697",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/19012",
          "name" : "19012",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/19179",
          "name" : "19179",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/19355",
          "name" : "19355",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/25945",
          "name" : "25945",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1015484",
          "name" : "1015484",
          "refsource" : "SECTRACK",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.debian.org/security/2007/dsa-1331",
          "name" : "DSA-1331",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.gentoo.org/security/en/glsa/glsa-200603-22.xml",
          "name" : "GLSA-200603-22",
          "refsource" : "GENTOO",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.hardened-php.net/advisory_012006.112.html",
          "name" : "http://www.hardened-php.net/advisory_012006.112.html",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDKSA-2006:028",
          "name" : "MDKSA-2006:028",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.php.net/release_5_1_2.php",
          "name" : "http://www.php.net/release_5_1_2.php",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16220",
          "name" : "16220",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0177",
          "name" : "ADV-2006-0177",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0369",
          "name" : "ADV-2006-0369",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24094",
          "name" : "php-session-response-splitting(24094)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://usn.ubuntu.com/261-1/",
          "name" : "USN-261-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple HTTP response splitting vulnerabilities in PHP 5.1.1 allow remote attackers to inject arbitrary HTTP headers via a crafted Set-Cookie header, related to the (1) session extension (aka ext/session) and the (2) header function."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:5.0:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:5.0:rc2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:5.0:rc3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:5.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:5.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:5.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:5.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:5.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:5.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:5.1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:5.1.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-13T23:03Z",
    "lastModifiedDate" : "2018-10-30T16:25Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0208",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "php",
            "product" : {
              "product_data" : [ {
                "product_name" : "php",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.2.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.2.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.2.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.3.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.3.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.3.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.3.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.3.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.3.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.3.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.3.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.3.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.3.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.3.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.3.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.4.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.4.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.1.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "ftp://patches.sgi.com/support/free/security/advisories/20060501-01-U.asc",
          "name" : "20060501-01-U",
          "refsource" : "SGI",
          "tags" : [ ]
        }, {
          "url" : "http://lists.suse.de/archive/suse-security-announce/2006-Feb/0008.html",
          "name" : "SUSE-SR:2006:004",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2006-0276.html",
          "name" : "RHSA-2006:0276",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2006-0549.html",
          "name" : "RHSA-2006:0549",
          "refsource" : "REDHAT",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18431",
          "name" : "18431",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18697",
          "name" : "18697",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/19012",
          "name" : "19012",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/19179",
          "name" : "19179",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/19355",
          "name" : "19355",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/19832",
          "name" : "19832",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/20210",
          "name" : "20210",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/20222",
          "name" : "20222",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/20951",
          "name" : "20951",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/21252",
          "name" : "21252",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/21564",
          "name" : "21564",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://support.avaya.com/elmodocs2/security/ASA-2006-129.htm",
          "name" : "http://support.avaya.com/elmodocs2/security/ASA-2006-129.htm",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://support.avaya.com/elmodocs2/security/ASA-2006-160.htm",
          "name" : "http://support.avaya.com/elmodocs2/security/ASA-2006-160.htm",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.gentoo.org/security/en/glsa/glsa-200603-22.xml",
          "name" : "GLSA-200603-22",
          "refsource" : "GENTOO",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDKSA-2006:028",
          "name" : "MDKSA-2006:028",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.php.net/ChangeLog-4.php#4.4.2",
          "name" : "http://www.php.net/ChangeLog-4.php#4.4.2",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.php.net/release_5_1_2.php",
          "name" : "http://www.php.net/release_5_1_2.php",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2006-0501.html",
          "name" : "RHSA-2006:0501",
          "refsource" : "REDHAT",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16803",
          "name" : "16803",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0177",
          "name" : "ADV-2006-0177",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0369",
          "name" : "ADV-2006-0369",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/2685",
          "name" : "ADV-2006-2685",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=178028",
          "name" : "https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=178028",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10064",
          "name" : "oval:org.mitre.oval:def:10064",
          "refsource" : "OVAL",
          "tags" : [ ]
        }, {
          "url" : "https://usn.ubuntu.com/261-1/",
          "name" : "USN-261-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple cross-site scripting (XSS) vulnerabilities in PHP 4.4.1 and 5.1.1, when display_errors and html_errors are on, allow remote attackers to inject arbitrary web script or HTML via inputs to PHP applications that are not filtered when they are included in the resulting error message."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.0:beta1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.0:beta2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.0:beta3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.0:beta4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.0:beta_4_patch1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.0:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.0:rc2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.2.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.2.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.2.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.2.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.3.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.3.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.3.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.3.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.3.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.3.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.3.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.3.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.3.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.3.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.3.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.3.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.4.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:4.4.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:5.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:5.0.0:beta1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:5.0.0:beta2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:5.0.0:beta3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:5.0.0:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:5.0.0:rc2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:5.0.0:rc3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:5.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:5.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:5.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:5.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:5.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:5.1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php:php:5.1.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:H/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "HIGH",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 2.6
        },
        "severity" : "LOW",
        "exploitabilityScore" : 4.9,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2006-01-13T23:03Z",
    "lastModifiedDate" : "2018-10-30T16:25Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0209",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "tanklogger",
            "product" : {
              "product_data" : [ {
                "product_name" : "tanklogger",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.4",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://attrition.org/pipermail/vim/2006-January/000480.html",
          "name" : "20060113 Verified TankLogger SQl inject by source inspection",
          "refsource" : "VIM",
          "tags" : [ ]
        }, {
          "url" : "http://evuln.com/vulns/26/summary.html",
          "name" : "http://evuln.com/vulns/26/summary.html",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18441",
          "name" : "18441",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/341",
          "name" : "341",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/22368",
          "name" : "22368",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/22369",
          "name" : "22369",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/421743/100/0/threaded",
          "name" : "20060112 [eVuln] TankLogger SQL Injection Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16228",
          "name" : "16228",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0153",
          "name" : "ADV-2006-0153",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24080",
          "name" : "tanklogger-generalfunctions-sql-injection(24080)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in general_functions.php in TankLogger 2.4 allows remote attackers to execute arbitrary SQL commands via the (1) livestock_id parameter to showInfo.php and (2) tank_id parameter, possibly to livestock.php."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tanklogger:tanklogger:2.4:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-14T01:03Z",
    "lastModifiedDate" : "2018-10-19T15:43Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0210",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "interspire",
            "product" : {
              "product_data" : [ {
                "product_name" : "trackpoint_nx",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18445",
          "name" : "18445",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.interspire.com/forum/showthread.php?p=29606",
          "name" : "http://www.interspire.com/forum/showthread.php?p=29606",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/22377",
          "name" : "22377",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/421740/100/0/threaded",
          "name" : "20060112 Interspire TrackPoint NX XSS Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16214",
          "name" : "16214",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0175",
          "name" : "ADV-2006-0175",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24112",
          "name" : "trackpointnx-login-xss(24112)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in index.php in Interspire TrackPoint NX before 0.1 allows remote attackers to inject arbitrary web script or HTML via the username parameter when using the Login page."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:interspire:trackpoint_nx:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-14T01:03Z",
    "lastModifiedDate" : "2018-10-19T15:43Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0211",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "helm_hosting",
            "product" : {
              "product_data" : [ {
                "product_name" : "helm_hosting_control_panel",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.2.8",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18492",
          "name" : "18492",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/22454",
          "name" : "22454",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/421791/100/0/threaded",
          "name" : "20060112 Helm XSS Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16234",
          "name" : "16234",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0203",
          "name" : "ADV-2006-0203",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.webhostautomation.com/webhost-301",
          "name" : "http://www.webhostautomation.com/webhost-301",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24139",
          "name" : "helm-forgotpassword-xss(24139)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in forgotPassword.asp in Helm Hosting Control Panel 3.2.8 and earlier allows remote attackers to inject arbitrary web script or HTML via the txtEmailAddress parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:helm_hosting:helm_hosting_control_panel:3.2.8:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-14T01:03Z",
    "lastModifiedDate" : "2018-10-19T15:43Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0212",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "toshiba",
            "product" : {
              "product_data" : [ {
                "product_name" : "bluetooth_stack",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.00.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.00.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.00.31a",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.00.32",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.01.03",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.10.00",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.20.00",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.20.01",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.20.02",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.20.04",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.00.01t",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.00.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.00.23t",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://aps.toshiba-tro.de/bluetooth/pages/driverinfo.php?txt=sp2",
          "name" : "http://aps.toshiba-tro.de/bluetooth/pages/driverinfo.php?txt=sp2",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://marc.info/?l=full-disclosure&m=113712413907526&w=2",
          "name" : "20060113 DMA[2006-0112a] - 'Toshiba Bluetooth Stack Directory Transversal'",
          "refsource" : "FULLDISC",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18437",
          "name" : "18437",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1015486",
          "name" : "1015486",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.digitalmunition.com/DMA%5B2006-0112a%5D.txt",
          "name" : "http://www.digitalmunition.com/DMA%5B2006-0112a%5D.txt",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/22380",
          "name" : "22380",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/421993/100/0/threaded",
          "name" : "20060113 DMA[2006-0112a] - 'Toshiba Bluetooth Stack Directory Transversal'",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16236",
          "name" : "16236",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0184",
          "name" : "ADV-2006-0184",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Directory traversal vulnerability in OBEX Push services in Toshiba Bluetooth Stack 4.00.23(T) and earlier allows remote attackers to upload arbitrary files to arbitrary remote locations specified by .. (dot dot) sequences, as demonstrated by ..\\\\ sequences in the RFILE argument of ussp-push."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:toshiba:bluetooth_stack:3.00.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:toshiba:bluetooth_stack:3.00.12:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:toshiba:bluetooth_stack:3.00.31a:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:toshiba:bluetooth_stack:3.00.32:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:toshiba:bluetooth_stack:3.01.03:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:toshiba:bluetooth_stack:3.10.00:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:toshiba:bluetooth_stack:3.20.00:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:toshiba:bluetooth_stack:3.20.01:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:toshiba:bluetooth_stack:3.20.02:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:toshiba:bluetooth_stack:3.20.04:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:toshiba:bluetooth_stack:4.00.01t:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:toshiba:bluetooth_stack:4.00.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:toshiba:bluetooth_stack:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "4.00.23t"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-14T01:03Z",
    "lastModifiedDate" : "2018-10-19T15:43Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0213",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "kolab",
            "product" : {
              "product_data" : [ {
                "product_name" : "kolab_groupware_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2005-12-15_pre2.1",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://kolab.org/security/kolab-vendor-notice-08.txt",
          "name" : "http://kolab.org/security/kolab-vendor-notice-08.txt",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18438",
          "name" : "18438",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/22381",
          "name" : "22381",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0186",
          "name" : "ADV-2006-0186",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24123",
          "name" : "kolab-smtp-logging(24123)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Kolab Server 2.0.1, 2.0.2 and development versions pre-2.1-20051215 and earlier, when authenticating users via secure SMTP, stores authentication credentials in plaintext in the postfix.log file, which allows local users to gain privileges."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:kolab:kolab_groupware_server:2.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:kolab:kolab_groupware_server:2.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:kolab:kolab_groupware_server:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "2005-12-15_pre2.1"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 4.6
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 3.9,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-14T01:03Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0214",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "indexcor",
            "product" : {
              "product_data" : [ {
                "product_name" : "ezdatabase",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.1.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://pridels0.blogspot.com/2006/01/ezdatabase-20-and-below.html",
          "name" : "http://pridels0.blogspot.com/2006/01/ezdatabase-20-and-below.html",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18043",
          "name" : "18043",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/351",
          "name" : "351",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16237",
          "name" : "16237",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24136",
          "name" : "ezdatabase-visitorupload-file-include(24136)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Eval injection vulnerability in ezDatabase 2.0 and earlier allows remote attackers to execute arbitrary PHP code via the db_id parameter to visitorupload.php, as demonstrated using phpinfo and include function calls."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:indexcor:ezdatabase:2.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:indexcor:ezdatabase:2.1.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-15T11:03Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0215",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "qualityebiz",
            "product" : {
              "product_data" : [ {
                "product_name" : "quality_ppc",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0_build_1644",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/ref/22/22352-qualityppc.txt",
          "name" : "http://osvdb.org/ref/22/22352-qualityppc.txt",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/22352",
          "name" : "22352",
          "refsource" : "OSVDB",
          "tags" : [ "Exploit" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in admin.php in QualityEBiz Quality PPC (QPPC) 1.0 build 1644 allows remote attackers to inject arbitrary web script or HTML via the cpage parameter.  NOTE: this issue might be resultant from CVE-2006-0216."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:qualityebiz:quality_ppc:1.0_build_1644:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-16T19:03Z",
    "lastModifiedDate" : "2008-09-05T20:58Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0216",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "qualityebiz",
            "product" : {
              "product_data" : [ {
                "product_name" : "quality_ppc",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0_build_1644",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/ref/22/22352-qualityppc.txt",
          "name" : "http://osvdb.org/ref/22/22352-qualityppc.txt",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://osvdb.org/ref/22/22353-qualityppc.txt",
          "name" : "http://osvdb.org/ref/22/22353-qualityppc.txt",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.osvdb.org/22353",
          "name" : "22353",
          "refsource" : "OSVDB",
          "tags" : [ "Exploit" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "admin.php in QualityEBiz Quality PPC (QPPC) 1.0 build 1644 allows remote attackers to obtain sensitive information, possibly the installation path of the application, via unspecified \"meta characters\" to the cpage parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:qualityebiz:quality_ppc:1.0_build_1644:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-16T19:03Z",
    "lastModifiedDate" : "2008-09-05T20:58Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0217",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ultimate_auction",
            "product" : {
              "product_data" : [ {
                "product_name" : "ultimate_auction",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.67",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://archives.neohapsis.com/archives/fulldisclosure/2006-01/0517.html",
          "name" : "20060115 Ultimate Auction <=3.67",
          "refsource" : "FULLDISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://secunia.com/advisories/18477",
          "name" : "18477",
          "refsource" : "SECUNIA",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/22443",
          "name" : "22443",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/22444",
          "name" : "22444",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16239",
          "name" : "16239",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16254",
          "name" : "16254",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0187",
          "name" : "ADV-2006-0187",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24138",
          "name" : "ultimate-auction-item-xss(24138)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple cross-site scripting (XSS) vulnerabilities in Ultimate Auction 3.67 allow remote attackers to inject arbitrary web script or HTML via the (1) item parameter in item.pl and (2) category parameter in itemlist.pl, which reflects the XSS in an error message. NOTE: the affected version might be wrong since the current version as of 20060116 is 3.6.1."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ultimate_auction:ultimate_auction:3.67:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-16T19:03Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0218",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "mybb",
            "product" : {
              "product_data" : [ {
                "product_name" : "mybb",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.00",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.01",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://community.mybboard.net/showthread.php?tid=5852",
          "name" : "http://community.mybboard.net/showthread.php?tid=5852",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple unspecified vulnerabilities in MyBulletinBoard (MyBB) before 1.0.2 have unspecified impact and attack vectors, related to (1) admin/moderate.php, (2) admin/themes.php, (3) inc/functions.php, (4) inc/functions_upload.php, (5) printthread.php, and (6) usercp.php, and probably related to SQL injection.  NOTE: it is likely that this issue subsumes CVE-2005-4602 and CVE-2005-4603.  However, since the vendor advisory is vague and additional files are mentioned, is is likely that this contains at least one distinct vulnerability from CVE-2005-4602 and CVE-2005-4603."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mybb:mybb:1.0:beta4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mybb:mybb:1.0:pr1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mybb:mybb:1.0:pr2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mybb:mybb:1.0:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mybb:mybb:1.0:rc2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mybb:mybb:1.0:rc3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mybb:mybb:1.0:rc4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mybb:mybb:1.00:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mybb:mybb:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.01"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "acInsufInfo" : true,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-16T21:03Z",
    "lastModifiedDate" : "2013-01-03T05:00Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0219",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "mybulletinboard",
            "product" : {
              "product_data" : [ {
                "product_name" : "mybulletinboard",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0_final",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0_preview_release_2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.01",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://community.mybboard.net/showthread.php?tid=5853&pid=35088#pid35088",
          "name" : "http://community.mybboard.net/showthread.php?tid=5853&pid=35088#pid35088",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://community.mybboard.net/showthread.php?tid=5853&pid=35151#pid35151",
          "name" : "http://community.mybboard.net/showthread.php?tid=5853&pid=35151#pid35151",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://community.mybboard.net/showthread.php?tid=5960",
          "name" : "http://community.mybboard.net/showthread.php?tid=5960",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16230",
          "name" : "16230",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24115",
          "name" : "mybb-usercp-script-sql-injection(24115)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The original distribution of MyBulletinBoard (MyBB) to update from older versions to 1.0.2 omits or includes older versions of certain critical files, which allows attackers to conduct (1) SQL injection attacks via an attachment name that is not properly handled by inc/functions_upload.php (CVE-2005-4602), and possibly (2) other attacks related to threadmode in usercp.php."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mybulletinboard:mybulletinboard:1.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mybulletinboard:mybulletinboard:1.0_final:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mybulletinboard:mybulletinboard:1.0_preview_release_2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mybulletinboard:mybulletinboard:1.01:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-16T21:03Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0220",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "codeworx_technologies",
            "product" : {
              "product_data" : [ {
                "product_name" : "dcp-portal",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.3.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.3.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/archive/1/421914/100/0/threaded",
          "name" : "20060113 DCP Portal Cross-Site Scripting Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16232",
          "name" : "16232",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24153",
          "name" : "dcpportal-calendar-search-xss(24153)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple cross-site scripting (XSS) vulnerabilities in DCP-Portal 5.3 through 6.1.1 allow remote attackers to inject arbitrary web script or HTML via (1) the day parameter in calendar.php and (2) the input form in search.php.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.  It is possible that this issue is resultant from an SQL injection problem in CVE-2005-4227.3 and CVE-2005-4227.13."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:codeworx_technologies:dcp-portal:5.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:codeworx_technologies:dcp-portal:5.3.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:codeworx_technologies:dcp-portal:5.3.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:codeworx_technologies:dcp-portal:6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:codeworx_technologies:dcp-portal:6.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:codeworx_technologies:dcp-portal:6.1.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-16T21:03Z",
    "lastModifiedDate" : "2018-10-19T15:43Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0221",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ddsn",
            "product" : {
              "product_data" : [ {
                "product_name" : "cm3cms",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.osvdb.org/22696",
          "name" : "22696",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/421941/100/0/threaded",
          "name" : "20060113 DDSN CMS Admin Panel SQL Injection Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16231",
          "name" : "16231",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24266",
          "name" : "cm3-login-sql-injection(24266)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in index.asp in the Admin Panel in Dragon Design Services Network (DDSN) cm3 content manager (CM3CMS) allows remote attackers to execute arbitrary SQL commands via the (1) username or (2) password."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ddsn:cm3cms:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-16T21:03Z",
    "lastModifiedDate" : "2018-10-19T15:43Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0222",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "alstrasoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "template_seller",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.osvdb.org/22746",
          "name" : "22746",
          "refsource" : "OSVDB",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/421916/100/0/threaded",
          "name" : "20060113 AlstraSoft Template Seller Pro Cross-Site Scripting Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16233",
          "name" : "16233",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24235",
          "name" : "template-seller-fullview-xss(24235)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in fullview.php in AlstraSoft Template Seller Pro allows remote attackers to inject arbitrary web script or HTML via the tempid parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:alstrasoft:template_seller:*:*:pro:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-16T21:03Z",
    "lastModifiedDate" : "2018-10-19T15:43Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0223",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "topcmm_computing",
            "product" : {
              "product_data" : [ {
                "product_name" : "123_flash_chat_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-22"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18455",
          "name" : "18455",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.123flashchat.com/flash-chat-server-v512.html",
          "name" : "http://www.123flashchat.com/flash-chat-server-v512.html",
          "refsource" : "MISC",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.osvdb.org/22440",
          "name" : "22440",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16235",
          "name" : "16235",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0198",
          "name" : "ADV-2006-0198",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24137",
          "name" : "123flashchat-user-directory-traversal(24137)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Directory traversal vulnerability in Shanghai TopCMM 123 Flash Chat Server Software 5.1 allows attackers to create or overwrite arbitrary files on the server via \"..\" (dot dot) sequences in the username field."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:topcmm_computing:123_flash_chat_server:5.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:topcmm_computing:123_flash_chat_server:5.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-16T21:03Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0224",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "libast",
            "product" : {
              "product_data" : [ {
                "product_name" : "libast",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.6.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://freshmeat.net/projects/libast/?branch_id=17907&release_id=217840",
          "name" : "http://freshmeat.net/projects/libast/?branch_id=17907&release_id=217840",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18586",
          "name" : "18586",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18632",
          "name" : "18632",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18916",
          "name" : "18916",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/373",
          "name" : "373",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2006/dsa-976",
          "name" : "DSA-976",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.gentoo.org/security/en/glsa/glsa-200601-14.xml",
          "name" : "GLSA-200601-14",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDKSA-2006:029",
          "name" : "MDKSA-2006:029",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/22735",
          "name" : "22735",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.rosiello.org/en/read_bugs.php?id=25",
          "name" : "http://www.rosiello.org/en/read_bugs.php?id=25",
          "refsource" : "MISC",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/423088/100/0/threaded",
          "name" : "20060125 Rosiello Security - Eterm-LibAST Advisory",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/423207/100/0/threaded",
          "name" : "20060123 [ Rosiello Security ] Eterm-LibAST Advisory",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/423366/100/0/threaded",
          "name" : "20060123 LibAST 0.7 Release Fixes Security Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16350",
          "name" : "16350",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0314",
          "name" : "ADV-2006-0314",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24303",
          "name" : "eterm-libast-filename-bo(24303)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Buffer overflow in Library of Assorted Spiffy Things (LibAST) 0.6.1 and earlier, as used in Eterm and possibly other software, allows local users to execute arbitrary code as the utmp user via a long -X command line argument (alternative configuration file name)."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:libast:libast:0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:libast:libast:0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:libast:libast:0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:libast:libast:0.6.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 4.6
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 3.9,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-25T02:03Z",
    "lastModifiedDate" : "2018-10-19T15:43Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0225",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "openbsd",
            "product" : {
              "product_data" : [ {
                "product_name" : "openssh",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.1p1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.2p1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0p1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.1p1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.2.2p1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.2.3p1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.3p1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.4p1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.5p1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.6.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.6.1p1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.6.1p2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.7.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.7.1p2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.8.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.8.1p1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.9.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.9.1p1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0p1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1p1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.2p1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.8/common/005_ssh.patch",
          "name" : "20060212 [3.8] 005: SECURITY FIX: February 12, 2006",
          "refsource" : "OPENBSD",
          "tags" : [ ]
        }, {
          "url" : "ftp://patches.sgi.com/support/free/security/advisories/20060703-01-U.asc",
          "name" : "20060703-01-P",
          "refsource" : "SGI",
          "tags" : [ ]
        }, {
          "url" : "http://blogs.sun.com/security/entry/sun_alert_102961_security_vulnerability",
          "name" : "http://blogs.sun.com/security/entry/sun_alert_102961_security_vulnerability",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://docs.info.apple.com/article.html?artnum=305214",
          "name" : "http://docs.info.apple.com/article.html?artnum=305214",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://itrc.hp.com/service/cki/docDisplay.do?docId=c00815112",
          "name" : "HPSBUX02178",
          "refsource" : "HP",
          "tags" : [ ]
        }, {
          "url" : "http://lists.apple.com/archives/security-announce/2007/Mar/msg00002.html",
          "name" : "APPLE-SA-2007-03-13",
          "refsource" : "APPLE",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18579",
          "name" : "18579",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18595",
          "name" : "18595",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18650",
          "name" : "18650",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18736",
          "name" : "18736",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18798",
          "name" : "18798",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18850",
          "name" : "18850",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18910",
          "name" : "18910",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18964",
          "name" : "18964",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18969",
          "name" : "18969",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18970",
          "name" : "18970",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/19159",
          "name" : "19159",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/20723",
          "name" : "20723",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/21129",
          "name" : "21129",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/21262",
          "name" : "21262",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/21492",
          "name" : "21492",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/21724",
          "name" : "21724",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/22196",
          "name" : "22196",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23241",
          "name" : "23241",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23340",
          "name" : "23340",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/23680",
          "name" : "23680",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24479",
          "name" : "24479",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/25607",
          "name" : "25607",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/25936",
          "name" : "25936",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/462",
          "name" : "462",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1015540",
          "name" : "1015540",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://slackware.com/security/viewer.php?l=slackware-security&y=2006&m=slackware-security.425802",
          "name" : "SSA:2006-045-06",
          "refsource" : "SLACKWARE",
          "tags" : [ ]
        }, {
          "url" : "http://sunsolve.sun.com/search/document.do?assetkey=1-26-102961-1",
          "name" : "102961",
          "refsource" : "SUNALERT",
          "tags" : [ ]
        }, {
          "url" : "http://support.avaya.com/elmodocs2/security/ASA-2006-158.htm",
          "name" : "http://support.avaya.com/elmodocs2/security/ASA-2006-158.htm",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://support.avaya.com/elmodocs2/security/ASA-2006-174.htm",
          "name" : "http://support.avaya.com/elmodocs2/security/ASA-2006-174.htm",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://support.avaya.com/elmodocs2/security/ASA-2006-262.htm",
          "name" : "http://support.avaya.com/elmodocs2/security/ASA-2006-262.htm",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://support.avaya.com/elmodocs2/security/ASA-2007-246.htm",
          "name" : "http://support.avaya.com/elmodocs2/security/ASA-2007-246.htm",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.gentoo.org/security/en/glsa/glsa-200602-11.xml",
          "name" : "GLSA-200602-11",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDKSA-2006:034",
          "name" : "MDKSA-2006:034",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.novell.com/linux/security/advisories/2006_08_openssh.html",
          "name" : "SUSE-SA:2006:008",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://www.openpkg.org/security/OpenPKG-SA-2006.003-openssh.html",
          "name" : "OpenPKG-SA-2006.003",
          "refsource" : "OPENPKG",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/22692",
          "name" : "22692",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/archives/fedora-announce-list/2006-January/msg00062.html",
          "name" : "FEDORA-2006-056",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2006-0044.html",
          "name" : "RHSA-2006:0044",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2006-0298.html",
          "name" : "RHSA-2006:0298",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2006-0698.html",
          "name" : "RHSA-2006:0698",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/425397/100/0/threaded",
          "name" : "FLSA-2006:168935",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16369",
          "name" : "16369",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.trustix.org/errata/2006/0004",
          "name" : "2006-0004",
          "refsource" : "TRUSTIX",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/usn-255-1",
          "name" : "USN-255-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA07-072A.html",
          "name" : "TA07-072A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vmware.com/support/vi3/doc/esx-3069097-patch.html",
          "name" : "http://www.vmware.com/support/vi3/doc/esx-3069097-patch.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.vmware.com/support/vi3/doc/esx-9986131-patch.html",
          "name" : "http://www.vmware.com/support/vi3/doc/esx-9986131-patch.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0306",
          "name" : "ADV-2006-0306",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/2490",
          "name" : "ADV-2006-2490",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/4869",
          "name" : "ADV-2006-4869",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0930",
          "name" : "ADV-2007-0930",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/2120",
          "name" : "ADV-2007-2120",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www14.software.ibm.com/webapp/set2/sas/f/hmc/power5/install/v52.Readme.html#MH00688",
          "name" : "http://www14.software.ibm.com/webapp/set2/sas/f/hmc/power5/install/v52.Readme.html#MH00688",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www14.software.ibm.com/webapp/set2/subscriptions/pqvcmjd?mode=18&ID=2751",
          "name" : "http://www14.software.ibm.com/webapp/set2/subscriptions/pqvcmjd?mode=18&ID=2751",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=174026",
          "name" : "https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=174026",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24305",
          "name" : "openssh-scp-command-execution(24305)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1138",
          "name" : "oval:org.mitre.oval:def:1138",
          "refsource" : "OVAL",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9962",
          "name" : "oval:org.mitre.oval:def:9962",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "scp in OpenSSH 4.2p1 allows attackers to execute arbitrary commands via filenames that contain shell metacharacters or spaces, which are expanded twice."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openbsd:openssh:3.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openbsd:openssh:3.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openbsd:openssh:3.0.1p1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openbsd:openssh:3.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openbsd:openssh:3.0.2p1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openbsd:openssh:3.0p1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openbsd:openssh:3.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openbsd:openssh:3.1p1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openbsd:openssh:3.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openbsd:openssh:3.2.2p1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openbsd:openssh:3.2.3p1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openbsd:openssh:3.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openbsd:openssh:3.3p1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openbsd:openssh:3.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openbsd:openssh:3.4p1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openbsd:openssh:3.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openbsd:openssh:3.5p1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openbsd:openssh:3.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openbsd:openssh:3.6.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openbsd:openssh:3.6.1p1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openbsd:openssh:3.6.1p2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openbsd:openssh:3.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openbsd:openssh:3.7.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openbsd:openssh:3.7.1p2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openbsd:openssh:3.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openbsd:openssh:3.8.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openbsd:openssh:3.8.1p1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openbsd:openssh:3.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openbsd:openssh:3.9.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openbsd:openssh:3.9.1p1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openbsd:openssh:4.0p1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openbsd:openssh:4.1p1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openbsd:openssh:4.2p1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 4.6
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 3.9,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-25T11:03Z",
    "lastModifiedDate" : "2018-10-19T15:43Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0226",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "freebsd",
            "product" : {
              "product_data" : [ {
                "product_name" : "freebsd",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-06:05.80211.asc",
          "name" : "FreeBSD-SA-06:05",
          "refsource" : "FREEBSD",
          "tags" : [ ]
        }, {
          "url" : "http://kernelwars.blogspot.com/2007/01/alive.html",
          "name" : "http://kernelwars.blogspot.com/2007/01/alive.html",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18353",
          "name" : "18353",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1015518",
          "name" : "1015518",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.blackhat.com/html/bh-europe-07/bh-eu-07-speakers.html#Eriksson",
          "name" : "http://www.blackhat.com/html/bh-europe-07/bh-eu-07-speakers.html#Eriksson",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/22537",
          "name" : "22537",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16296",
          "name" : "16296",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.signedness.org/advisories/sps-0x1.txt",
          "name" : "http://www.signedness.org/advisories/sps-0x1.txt",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24192",
          "name" : "bsd-ieee80211-bo(24192)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Integer overflow in IEEE 802.11 network subsystem (ieee80211_ioctl.c) in FreeBSD before 6.0-STABLE, while scanning for wireless networks, allows remote attackers to execute arbitrary code by broadcasting crafted (1) beacon or (2) probe response frames."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:freebsd:freebsd:6.0:release:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:freebsd:freebsd:6.0:stable:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-19T01:03Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0227",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "sun",
            "product" : {
              "product_data" : [ {
                "product_name" : "solaris",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "sunos",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.9",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18498",
          "name" : "18498",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/19087",
          "name" : "19087",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1015492",
          "name" : "1015492",
          "refsource" : "SECTRACK",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://sunsolve.sun.com/search/document.do?assetkey=1-26-102033-1",
          "name" : "102033",
          "refsource" : "SUNALERT",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://support.avaya.com/elmodocs2/security/ASA-2006-056.htm",
          "name" : "http://support.avaya.com/elmodocs2/security/ASA-2006-056.htm",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/22441",
          "name" : "22441",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/22442",
          "name" : "22442",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16245",
          "name" : "16245",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0200",
          "name" : "ADV-2006-0200",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24127",
          "name" : "solaris-lpsched-dos(24127)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A662",
          "name" : "oval:org.mitre.oval:def:662",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple unspecified vulnerabilities in lpsched in Sun Solaris 8, 9, and 10 allow local users to delete arbitrary files or disable the LP print service via unknown attack vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:sun:solaris:9.0:*:sparc:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:sun:solaris:10.0:*:sparc:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:sun:solaris:10.0:*:x86:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:sun:sunos:5.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:sun:sunos:5.9:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:H/Au:N/C:N/I:P/A:P",
          "accessVector" : "LOCAL",
          "accessComplexity" : "HIGH",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 2.6
        },
        "severity" : "LOW",
        "exploitabilityScore" : 1.9,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-17T20:07Z",
    "lastModifiedDate" : "2018-10-30T16:26Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0228",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "grsecurity",
            "product" : {
              "product_data" : [ {
                "product_name" : "grsecurity_kernel_patch",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.1.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.1.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.1.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.1.7",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18458",
          "name" : "18458",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.grsecurity.org/news.php#grsec218",
          "name" : "http://www.grsecurity.org/news.php#grsec218",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16261",
          "name" : "16261",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0199",
          "name" : "ADV-2006-0199",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24156",
          "name" : "grsecurity-rbac-admin-privileges(24156)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The RBAC functionality in grsecurity before 2.1.8 does not properly handle when the admin role creates a service and then exits the shell without unauthenticating, which causes the service to be restarted with the admin role still active."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:grsecurity:grsecurity_kernel_patch:2.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:grsecurity:grsecurity_kernel_patch:2.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:grsecurity:grsecurity_kernel_patch:2.1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:grsecurity:grsecurity_kernel_patch:2.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:grsecurity:grsecurity_kernel_patch:2.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:grsecurity:grsecurity_kernel_patch:2.1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:grsecurity:grsecurity_kernel_patch:2.1.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:grsecurity:grsecurity_kernel_patch:2.1.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:grsecurity:grsecurity_kernel_patch:2.1.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:grsecurity:grsecurity_kernel_patch:2.1.7:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.2
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 3.9,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-17T21:03Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0229",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "wehnus",
            "product" : {
              "product_data" : [ {
                "product_name" : "wehntrust",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/archive/1/422020/100/0/threaded",
          "name" : "20060116 WehnTrust - When you have to trust Wehntrust",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/422046/100/0/threaded",
          "name" : "20060116 Re: [Full-disclosure] WehnTrust - When you have to trust Wehntrust",
          "refsource" : "BUGTRAQ",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16268",
          "name" : "16268",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.wehnus.com/downloads.pl",
          "name" : "http://www.wehnus.com/downloads.pl",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24315",
          "name" : "wehntrust-service-start-file-execution(24315)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unquoted Windows search path vulnerability in Wehntrust might allow local users to gain privileges via a malicious \"program.exe\" file in the C: folder, which is run when Wehntrust creates the autostart key."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wehnus:wehntrust:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:N/I:P/A:N",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 2.1
        },
        "severity" : "LOW",
        "exploitabilityScore" : 3.9,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-17T21:03Z",
    "lastModifiedDate" : "2018-10-19T15:43Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0230",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "symantec",
            "product" : {
              "product_data" : [ {
                "product_name" : "antivirus_scan_engine",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.0.0.24",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://archives.neohapsis.com/archives/vulnwatch/2006-q2/0010.html",
          "name" : "20060421 Rapid7 Advisory R7-0021: Symantec Scan Engine Authentication Fundamental Design Error",
          "refsource" : "VULNWATCH",
          "tags" : [ "Exploit", "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/19734",
          "name" : "19734",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/118388",
          "name" : "VU#118388",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/431724/100/0/threaded",
          "name" : "20060421 Rapid7 Advisory R7-0021: Symantec Scan Engine Authentication Fundamental Design Error",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/431734/100/0/threaded",
          "name" : "20060421 [Symantec Security Advisor] Symantec Scan Engine Multiple Vulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/17637",
          "name" : "17637",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.symantec.com/avcenter/security/Content/2006.04.21.html",
          "name" : "http://www.symantec.com/avcenter/security/Content/2006.04.21.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/1464",
          "name" : "ADV-2006-1464",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/25972",
          "name" : "sse-unauth-admin-access(25972)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Symantec Scan Engine 5.0.0.24, and possibly other versions before 5.1.0.7, uses a client-side check to verify a password, which allows remote attackers to gain administrator privileges via a modified client that sends certain XML requests."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:antivirus_scan_engine:5.0.0.24:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-04-25T01:02Z",
    "lastModifiedDate" : "2018-10-19T15:43Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0231",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "symantec",
            "product" : {
              "product_data" : [ {
                "product_name" : "antivirus_scan_engine",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.0.0.24",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://archives.neohapsis.com/archives/vulnwatch/2006-q2/0011.html",
          "name" : "20060421 Rapid7 Advisory R7-0022: Symantec Scan Engine Known Immutable DSA Private Key",
          "refsource" : "VULNWATCH",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/19734",
          "name" : "19734",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1015974",
          "name" : "1015974",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/431725/100/0/threaded",
          "name" : "20060421 Rapid7 Advisory R7-0022: Symantec Scan Engine Known Immutable DSA Private Key",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/431734/100/0/threaded",
          "name" : "20060421 [Symantec Security Advisor] Symantec Scan Engine Multiple Vulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/17637",
          "name" : "17637",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.symantec.com/avcenter/security/Content/2006.04.21.html",
          "name" : "http://www.symantec.com/avcenter/security/Content/2006.04.21.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/1464",
          "name" : "ADV-2006-1464",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/25973",
          "name" : "sse-insecure-private-key(25973)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Symantec Scan Engine 5.0.0.24, and possibly other versions before 5.1.0.7, uses the same private DSA key for each installation, which allows remote attackers to conduct man-in-the-middle attacks and decrypt communications."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:antivirus_scan_engine:5.0.0.24:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 6.4
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-04-25T01:02Z",
    "lastModifiedDate" : "2018-10-19T15:43Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0232",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "symantec",
            "product" : {
              "product_data" : [ {
                "product_name" : "antivirus_scan_engine",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.0.0.24",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://archives.neohapsis.com/archives/vulnwatch/2006-q2/0012.html",
          "name" : "20060421 Rapid7 Advisory R7-0023: Symantec Scan Engine File Disclosure Vulnerability",
          "refsource" : "VULNWATCH",
          "tags" : [ "Exploit", "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/19734",
          "name" : "19734",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/758",
          "name" : "758",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/759",
          "name" : "759",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1015974",
          "name" : "1015974",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/431728/100/0/threaded",
          "name" : "20060421 Rapid7 Advisory R7-0023: Symantec Scan Engine File Disclosure Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/431734/100/0/threaded",
          "name" : "20060421 [Symantec Security Advisor] Symantec Scan Engine Multiple Vulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/17637",
          "name" : "17637",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.symantec.com/avcenter/security/Content/2006.04.21.html",
          "name" : "http://www.symantec.com/avcenter/security/Content/2006.04.21.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/1464",
          "name" : "ADV-2006-1464",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/25974",
          "name" : "sse-unauth-file-access(25974)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Symantec Scan Engine 5.0.0.24, and possibly other versions before 5.1.0.7, stores sensitive log and virus definition files under the web root with insufficient access control, which allows remote attackers to obtain the information via direct requests."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:antivirus_scan_engine:5.0.0.24:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-04-25T01:02Z",
    "lastModifiedDate" : "2018-10-19T15:43Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0233",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microblog",
            "product" : {
              "product_data" : [ {
                "product_name" : "microblog",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0_rc10",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://evuln.com/vulns/36/summary.html",
          "name" : "http://evuln.com/vulns/36/summary.html",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1015496",
          "name" : "1015496",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/422145/100/0/threaded",
          "name" : "20060117 [eVuln] microBlog BBCode XSS Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16272",
          "name" : "16272",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24140",
          "name" : "microblog-functions-xss(24140)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in functions.php in microBlog 2.0 RC-10 allows remote attackers to inject arbitrary web script and HTML via a javascript: URI in a [url] BBcode tag."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microblog:microblog:2.0_rc10:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2006-01-18T00:07Z",
    "lastModifiedDate" : "2018-10-19T15:43Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0234",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microblog",
            "product" : {
              "product_data" : [ {
                "product_name" : "microblog",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0_rc10",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://evuln.com/vulns/35/summary.html",
          "name" : "http://evuln.com/vulns/35/summary.html",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18442",
          "name" : "18442",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1015496",
          "name" : "1015496",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/22512",
          "name" : "22512",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/422141/100/0/threaded",
          "name" : "20060117 [eVuln] microBlog SQL Injection Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16270",
          "name" : "16270",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0239",
          "name" : "ADV-2006-0239",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24132",
          "name" : "microblog-index-sql-injection(24132)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in index.php in microBlog 2.0 RC-10 allows remote attackers to execute arbitrary SQL commands via the (1) month and (2) year parameters."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microblog:microblog:2.0_rc10:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-18T00:07Z",
    "lastModifiedDate" : "2018-10-19T15:43Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0235",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "white_angle",
            "product" : {
              "product_data" : [ {
                "product_name" : "white_album",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.5",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18460",
          "name" : "18460",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.biyosecurity.be/bugs/whitealbum.txt",
          "name" : "http://www.biyosecurity.be/bugs/whitealbum.txt",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/22520",
          "name" : "22520",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/422105/100/0/threaded",
          "name" : "20060116 White Album Sql &#304;njection biyosecurity.be",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16247",
          "name" : "16247",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0241",
          "name" : "ADV-2006-0241",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24271",
          "name" : "whitealbum-pictures-sql-injection(24271)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in WhiteAlbum 2.5 allows remote attackers to execute arbitrary SQL commands via the dir parameter to pictures.php."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:white_angle:white_album:2.5:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-18T01:07Z",
    "lastModifiedDate" : "2018-10-19T15:43Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0236",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "mozilla",
            "product" : {
              "product_data" : [ {
                "product_name" : "thunderbird",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-94"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/15907",
          "name" : "15907",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/secunia_research/2005-22/advisory",
          "name" : "http://secunia.com/secunia_research/2005-22/advisory",
          "refsource" : "MISC",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDKSA-2006:021",
          "name" : "MDKSA-2006:021",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/422148/100/0/threaded",
          "name" : "20060117 Secunia Research: Mozilla Thunderbird Attachment SpoofingVulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16271",
          "name" : "16271",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0230",
          "name" : "ADV-2006-0230",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://bugzilla.mozilla.org/show_bug.cgi?id=300246",
          "name" : "https://bugzilla.mozilla.org/show_bug.cgi?id=300246",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24164",
          "name" : "thunderbird-attachment-ext-spoofing(24164)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "GUI display truncation vulnerability in Mozilla Thunderbird 1.0.2, 1.0.6, and 1.0.7 allows user-assisted attackers to execute arbitrary code via an attachment with a filename containing a large number of spaces ending with a dangerous extension that is not displayed by Thunderbird, along with an inconsistent Content-Type header, which could be used to trick a user into downloading dangerous content by dragging or saving the attachment."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:thunderbird:1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:thunderbird:1.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:thunderbird:1.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:thunderbird:1.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:thunderbird:1.0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:thunderbird:1.0.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:thunderbird:1.5:beta2:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:H/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "HIGH",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.1
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 4.9,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2006-01-18T01:07Z",
    "lastModifiedDate" : "2018-10-19T15:43Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0237",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "gtp",
            "product" : {
              "product_data" : [ {
                "product_name" : "icommerce",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18470",
          "name" : "18470",
          "refsource" : "SECUNIA",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16255",
          "name" : "16255",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0214",
          "name" : "ADV-2006-0214",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24150",
          "name" : "gtpicommerce-index-xss(24150)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in index.php in GTP iCommerce allows remote attackers to inject arbitrary web script or HTML via the (1) cat and (2) subcat parameters.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:gtp:icommerce:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-18T01:07Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0238",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "gamerz",
            "product" : {
              "product_data" : [ {
                "product_name" : "wp-stats",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/ref/22/22450-wpstats.txt",
          "name" : "http://osvdb.org/ref/22/22450-wpstats.txt",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18471",
          "name" : "18471",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.lesterchan.net/blogs/",
          "name" : "http://www.lesterchan.net/blogs/",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.lesterchan.net/blogs/archives/2006/01/18/wp-stats-sql-injection-vulnerability",
          "name" : "http://www.lesterchan.net/blogs/archives/2006/01/18/wp-stats-sql-injection-vulnerability",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/22450",
          "name" : "22450",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16241",
          "name" : "16241",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0192",
          "name" : "ADV-2006-0192",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24163",
          "name" : "wpstats-script-sql-injection(24163)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in wp-stats.php in GaMerZ WP-Stats 2.0 allows remote attackers to execute arbitrary SQL commands via the author parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:gamerz:wp-stats:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "2.0"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-18T01:07Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0239",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "8pixel.net",
            "product" : {
              "product_data" : [ {
                "product_name" : "simple_blog",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18488",
          "name" : "18488",
          "refsource" : "SECUNIA",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://www.hackerscenter.com/archive/view.asp?id=21926",
          "name" : "http://www.hackerscenter.com/archive/view.asp?id=21926",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/22448",
          "name" : "22448",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/422102/100/0/threaded",
          "name" : "20060114 [HSC Security Group] Multiple SQL injection/XSS in SimpleBlog 2.1",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16243",
          "name" : "16243",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0194",
          "name" : "ADV-2006-0194",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24154",
          "name" : "simpleblog-comment-xss(24154)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple cross-site scripting (XSS) vulnerabilities in Simple Blog 2.1 allow remote attackers to inject arbitrary web script or HTML via (1) a comment to comments.asp and (2) possibly certain other fields in unspecified scripts."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:8pixel.net:simple_blog:2.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-18T01:07Z",
    "lastModifiedDate" : "2018-10-19T15:43Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0240",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "8pixel.net",
            "product" : {
              "product_data" : [ {
                "product_name" : "simple_blog",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.1",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18488",
          "name" : "18488",
          "refsource" : "SECUNIA",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://www.hackerscenter.com/archive/view.asp?id=21926",
          "name" : "http://www.hackerscenter.com/archive/view.asp?id=21926",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/22447",
          "name" : "22447",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/422102/100/0/threaded",
          "name" : "20060114 [HSC Security Group] Multiple SQL injection/XSS in SimpleBlog 2.1",
          "refsource" : "BUGTRAQ",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16243",
          "name" : "16243",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0194",
          "name" : "ADV-2006-0194",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24155",
          "name" : "simpleblog-month-sql-injection(24155)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple SQL injection vulnerabilities in Simple Blog 2.1 allow remote attackers to execute arbitrary SQL commands via the month parameter in an archives view operation and possibly certain other parameters in unspecified scripts."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:8pixel.net:simple_blog:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "2.1"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-18T01:07Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0241",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "webmobo",
            "product" : {
              "product_data" : [ {
                "product_name" : "wbnews",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.1.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18499",
          "name" : "18499",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/422133/100/0/threaded",
          "name" : "20060117 XSS in WBNews < = v1.1.0",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16277",
          "name" : "16277",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0237",
          "name" : "ADV-2006-0237",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting vulnerability in WBNews 1.1.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the Name field."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:webmobo:wbnews:1.1.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-18T01:07Z",
    "lastModifiedDate" : "2018-10-19T15:43Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0242",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "php_fusebox",
            "product" : {
              "product_data" : [ {
                "product_name" : "php_fusebox",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.0.6",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://securityreason.com/securityalert/355",
          "name" : "355",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/422124/100/0/threaded",
          "name" : "20060117 IndonesiaHack Advisory HTML injection in PHP Fusebox",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16274",
          "name" : "16274",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting vulnerability in index.php in PHP Fusebox 4.0.6 allows remote attackers to inject arbitrary web script or HTML via the fuseaction parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php_fusebox:php_fusebox:4.0.6:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 6.4
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-18T01:07Z",
    "lastModifiedDate" : "2018-10-19T15:43Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0243",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "smbcms",
            "product" : {
              "product_data" : [ {
                "product_name" : "smbcms",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18454",
          "name" : "18454",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/22494",
          "name" : "22494",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16281",
          "name" : "16281",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0229",
          "name" : "ADV-2006-0229",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24187",
          "name" : "smbcms-sitesearch-xss(24187)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in SMBCMS 2.1 allows remote attackers to inject arbitrary web script or HTML via the text parameter, which is used by the \"Search Site\" field.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:smbcms:smbcms:2.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-18T01:51Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0244",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "phpxplorer",
            "product" : {
              "product_data" : [ {
                "product_name" : "phpxplorer",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.9.33",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18518",
          "name" : "18518",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/353",
          "name" : "353",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.arrelnet.com/advisories/adv20060116.html",
          "name" : "http://www.arrelnet.com/advisories/adv20060116.html",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/421997/100/0/threaded",
          "name" : "20060116 Directory traversal in phpXplorer",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/422158/100/0/threaded",
          "name" : "20060116 Re: Directory traversal in phpXplorer",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16263",
          "name" : "16263",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0232",
          "name" : "ADV-2006-0232",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39982",
          "name" : "phpxplorer-sshare-directory-traversal(39982)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "** DISPUTED ** Directory traversal vulnerability in workspaces.php in phpXplorer 0.9.33 allows remote attackers to include arbitrary files via a .. (dot dot) and trailing null byte (%00) in the sShare parameter.  NOTE: a followup post claims that this is not a vulnerability since the functionality of phpXplorer supports the upload of PHP files, which would not cross privilege boundaries since the PHP functionality would support read access outside the web root."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:phpxplorer:phpxplorer:0.9.33:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-18T01:51Z",
    "lastModifiedDate" : "2018-10-19T15:43Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0245",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "devellion",
            "product" : {
              "product_data" : [ {
                "product_name" : "cubecart",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.0.7-pl1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://bugs.cubecart.com/?do=details&id=459",
          "name" : "http://bugs.cubecart.com/?do=details&id=459",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://lostmon.blogspot.com/2006/01/cubecart-307-pl1-indexphp-multiple.html",
          "name" : "http://lostmon.blogspot.com/2006/01/cubecart-307-pl1-indexphp-multiple.html",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18519",
          "name" : "18519",
          "refsource" : "SECUNIA",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/22471",
          "name" : "22471",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16259",
          "name" : "16259",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0227",
          "name" : "ADV-2006-0227",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24177",
          "name" : "cubecart-index-script-xss(24177)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple cross-site scripting (XSS) vulnerabilities in CubeCart 3.0.7-pl1 allow remote attackers to inject arbitrary web script or HTML via the (3) redir, (4) productId, (5) docId, (6) act, and (7) catId parameters in index.php; and the (8) username field in a login action in index.php.  NOTE: the cart.php/redir and index.php/searchStr vectors are already covered by CVE-2005-3152."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:devellion:cubecart:3.0.7-pl1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-18T01:51Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0246",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "widexl",
            "product" : {
              "product_data" : [ {
                "product_name" : "download_tracker",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0.6",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/ref/22/22462-widexl.txt",
          "name" : "http://osvdb.org/ref/22/22462-widexl.txt",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://secunia.com/advisories/18472",
          "name" : "18472",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/22462",
          "name" : "22462",
          "refsource" : "OSVDB",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16265",
          "name" : "16265",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0213",
          "name" : "ADV-2006-0213",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24161",
          "name" : "downloadtracker-down-xss(24161)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in down.pl in Widexl Download Tracker 1.06 allows remote attackers to inject arbitrary web script or HTML via the ID parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:widexl:download_tracker:1.0.6:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-18T01:51Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0247",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "netbula",
            "product" : {
              "product_data" : [ {
                "product_name" : "anyboard",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9.9.5.6",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/ref/22/22461-anyboard.txt",
          "name" : "http://osvdb.org/ref/22/22461-anyboard.txt",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://secunia.com/advisories/18469",
          "name" : "18469",
          "refsource" : "SECUNIA",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/22461",
          "name" : "22461",
          "refsource" : "OSVDB",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16264",
          "name" : "16264",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0188",
          "name" : "ADV-2006-0188",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24167",
          "name" : "netbula-anyboard-script-xss(24167)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in anyboard.cgi in Netbula Anyboard 9.9 and earlier allows remote attackers to inject arbitrary web script or HTML via the tK parameter in a find command."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:netbula:anyboard:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "9.9.5.6"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-18T01:51Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0248",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "intracom",
            "product" : {
              "product_data" : [ {
                "product_name" : "jetspeed",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "500",
                    "version_affected" : "="
                  }, {
                    "version_value" : "520",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://blog.globalnetworks.gr/?p=4",
          "name" : "http://blog.globalnetworks.gr/?p=4",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18483",
          "name" : "18483",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0218",
          "name" : "ADV-2006-0218",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24304",
          "name" : "virata-emweb-unauth-access(24304)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Virata-EmWeb web server 6_1_0, as used in (1) Intracom JetSpeed 500 and 520 and (2) Allied Data Technologies CopperJet 811 RouterPlus, allows remote attackers to access privileged information, such as user lists and configuration settings, via direct HTTP requests."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:intracom:jetspeed:500:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:intracom:jetspeed:520:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-18T01:51Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0249",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "bitdamaged",
            "product" : {
              "product_data" : [ {
                "product_name" : "geoblog",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "mod_1.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://evuln.com/vulns/33/summary.html",
          "name" : "http://evuln.com/vulns/33/summary.html",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://secunia.com/advisories/18504",
          "name" : "18504",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1015493",
          "name" : "1015493",
          "refsource" : "SECTRACK",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.osvdb.org/22463",
          "name" : "22463",
          "refsource" : "OSVDB",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16249",
          "name" : "16249",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0191",
          "name" : "ADV-2006-0191",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24146",
          "name" : "geoBlog-viewcat-sql-injection(24146)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in viewcat.php in BitDamaged geoBlog MOD_1.0 allows remote attackers to execute arbitrary SQL commands, then steal credentials and upload files, via the cat parameter ($tmpCategory variable)."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bitdamaged:geoblog:mod_1.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-18T01:51Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0250",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "carnegie_mellon_university",
            "product" : {
              "product_data" : [ {
                "product_name" : "snmptrapd",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.7",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18525",
          "name" : "18525",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.digitalarmaments.com/2006040164883273.html",
          "name" : "http://www.digitalarmaments.com/2006040164883273.html",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/22493",
          "name" : "22493",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/422086/100/0/threaded",
          "name" : "20060116 Digital Armaments Security Advisory 01.16.2006: CMU SNMP utilities snmptrad Format String Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16267",
          "name" : "16267",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0234",
          "name" : "ADV-2006-0234",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24178",
          "name" : "cmusnmp-snmpinput-format-string(24178)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Format string vulnerability in the snmp_input function in snmptrapd in CMU SNMP utilities (cmu-snmp) allows remote attackers to execute arbitrary code by sending crafted SNMP messages to UDP port 162."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:carnegie_mellon_university:snmptrapd:3.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:carnegie_mellon_university:snmptrapd:3.7:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.4
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-18T01:51Z",
    "lastModifiedDate" : "2018-10-19T15:43Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0251",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "faq-o-matic",
            "product" : {
              "product_data" : [ {
                "product_name" : "faq-o-matic",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.711",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/ref/22/22439-faqomatic.txt",
          "name" : "http://osvdb.org/ref/22/22439-faqomatic.txt",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://secunia.com/advisories/18468",
          "name" : "18468",
          "refsource" : "SECUNIA",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/22439",
          "name" : "22439",
          "refsource" : "OSVDB",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16251",
          "name" : "16251",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0189",
          "name" : "ADV-2006-0189",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24165",
          "name" : "faqomatic-fom-xss(24165)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in fom.cgi in Faq-O-Matic 2.711 allows remote attackers to inject arbitrary web script or HTML via the (1) _duration, (2) file, and (3) cmd parameters."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:faq-o-matic:faq-o-matic:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "2.711"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-18T01:51Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0252",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "benders_calendar",
            "product" : {
              "product_data" : [ {
                "product_name" : "benders_calendar",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://evuln.com/vulns/30/summary.html",
          "name" : "http://evuln.com/vulns/30/summary.html",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18462",
          "name" : "18462",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1015491",
          "name" : "1015491",
          "refsource" : "SECTRACK",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/22449",
          "name" : "22449",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/422052/100/0/threaded",
          "name" : "20060115 [eVuln] Benders Calendar SQL Injection",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16242",
          "name" : "16242",
          "refsource" : "BID",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0190",
          "name" : "ADV-2006-0190",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24120",
          "name" : "benderscalendar-sql-injection(24120)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in Benders Calendar 1.0 allows remote attackers to execute arbitrary SQL commands via multiple parameters, as demonstrated by the (1) year, (2) month, and (3) day parameters."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:benders_calendar:benders_calendar:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.0"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-18T01:51Z",
    "lastModifiedDate" : "2018-10-19T15:43Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0253",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ambicom",
            "product" : {
              "product_data" : [ {
                "product_name" : "blue_neighbors",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.50_build_2500",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18466",
          "name" : "18466",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/366",
          "name" : "366",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.digitalmunition.com/DMA%5B2006-0115a%5D.txt",
          "name" : "http://www.digitalmunition.com/DMA%5B2006-0115a%5D.txt",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/422481/100/0/threaded",
          "name" : "20060120 DMA[2006-0115a] - 'AmbiCom Bluetooth Object Push Overflow'",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16258",
          "name" : "16258",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0219",
          "name" : "ADV-2006-0219",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24179",
          "name" : "ambicom-bluetooth-objectpush-bo(24179)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Buffer overflow in the Bluetooth OBEX Object Push service in \"Blue Neighbors.EXE\" in AmbiCom Blue Neighbors 2.50 Build 2500 and earlier allows remote attackers to execute arbitrary code via a long file name, as demonstrated via a long RFILE argument to ussp-push."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ambicom:blue_neighbors:2.50_build_2500:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:H/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "HIGH",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.1
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 4.9,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2006-01-18T01:51Z",
    "lastModifiedDate" : "2018-10-19T15:43Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0254",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apache",
            "product" : {
              "product_data" : [ {
                "product_name" : "geronimo",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://issues.apache.org/jira/browse/GERONIMO-1474",
          "name" : "http://issues.apache.org/jira/browse/GERONIMO-1474",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2008-0630.html",
          "name" : "RHSA-2008:0630",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18485",
          "name" : "18485",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/31493",
          "name" : "31493",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.oliverkarow.de/research/geronimo_css.txt",
          "name" : "http://www.oliverkarow.de/research/geronimo_css.txt",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2008-0261.html",
          "name" : "RHSA-2008:0261",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/421996/100/0/threaded",
          "name" : "20060115 Apache Geronimo 1.0 - CSS and persistent HTML-Injectionvulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16260",
          "name" : "16260",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0217",
          "name" : "ADV-2006-0217",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24158",
          "name" : "geronimo-jspexamples-xss(24158)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24159",
          "name" : "geronimo-webaccesslog-viewer-xss(24159)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://issues.apache.org/jira/secure/ReleaseNote.jspa?version=12310181&styleName=Html&projectId=10220&Create=Create",
          "name" : "https://issues.apache.org/jira/secure/ReleaseNote.jspa?version=12310181&styleName=Html&projectId=10220&Create=Create",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple cross-site scripting (XSS) vulnerabilities in Apache Geronimo 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) time parameter to cal2.jsp and (2) any invalid parameter, which causes an XSS when the log file is viewed by the Web-Access-Log viewer."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:geronimo:1.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-18T01:51Z",
    "lastModifiedDate" : "2018-10-19T15:43Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0255",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "checkpoint",
            "product" : {
              "product_data" : [ {
                "product_name" : "vpn-1",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secdev.zoller.lu/research/checkpoint.txt",
          "name" : "http://secdev.zoller.lu/research/checkpoint.txt",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/422263/100/0/threaded",
          "name" : "20060117 [ TZO-012006 ] Checkpoint VPN-1 SecureClient insecure usage of CreateProcess()",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16290",
          "name" : "16290",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0258",
          "name" : "ADV-2006-0258",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unquoted Windows search path vulnerability in Check Point VPN-1 SecureClient might allow local users to gain privileges via a malicious \"program.exe\" file in the C: folder, which is run when SecureClient attempts to launch the Sr_GUI.exe program."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:checkpoint:vpn-1:*:*:fp1:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:checkpoint:vpn-1:4.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:checkpoint:vpn-1:4.1:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:checkpoint:vpn-1:4.1:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:checkpoint:vpn-1:4.1:sp3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:checkpoint:vpn-1:4.1:sp4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:checkpoint:vpn-1:4.1:sp5:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:checkpoint:vpn-1:4.1:sp5a:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:checkpoint:vpn-1:4.1:sp6:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.2
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 3.9,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-18T01:51Z",
    "lastModifiedDate" : "2018-10-19T15:43Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0256",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "database_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.1.7.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0.1.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.2.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.0.3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18493",
          "name" : "18493",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18608",
          "name" : "18608",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1015499",
          "name" : "1015499",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/545804",
          "name" : "VU#545804",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2006-082403.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2006-082403.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16287",
          "name" : "16287",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0243",
          "name" : "ADV-2006-0243",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0323",
          "name" : "ADV-2006-0323",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Advanced Queuing component of Oracle Database server 8.1.7.4, 9.0.1.5, 9.2.0.6, 10.1.0.3 has unspecified impact and attack vectors, as identified by Oracle Vuln# DB01."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database_server:8.1.7.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database_server:9.0.1.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database_server:9.2.0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database_server:10.1.0.3:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "acInsufInfo" : true,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-18T11:03Z",
    "lastModifiedDate" : "2012-10-23T01:56Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0257",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "database_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9.2.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.2.0.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18493",
          "name" : "18493",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18608",
          "name" : "18608",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1015499",
          "name" : "1015499",
          "refsource" : "SECTRACK",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/545804",
          "name" : "VU#545804",
          "refsource" : "CERT-VN",
          "tags" : [ "Third Party Advisory", "US Government Resource" ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2006-082403.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2006-082403.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/22540",
          "name" : "22540",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16287",
          "name" : "16287",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0243",
          "name" : "ADV-2006-0243",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0323",
          "name" : "ADV-2006-0323",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24321",
          "name" : "oracle-january2006-update(24321)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Change Data Capture component of Oracle Database server 9.2.0.7, 10.1.0.5, and 10.2.0.1 has unspecified impact and attack vectors, as identified by Oracle Vuln# DB02.  NOTE: details are unavailable from Oracle, but they have not publicly disputed a claim by a reliable independent researcher that states that the problem is SQL injection in the CDC_ALLOCATE_LOCK function of the DBMS_CDC_UTILITY package."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database_server:9.2.0.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database_server:10.1.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database_server:10.2.0.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "acInsufInfo" : true,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-18T11:03Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0258",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "database_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.1.7.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0.1.5",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18493",
          "name" : "18493",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18608",
          "name" : "18608",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1015499",
          "name" : "1015499",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/545804",
          "name" : "VU#545804",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2006-082403.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2006-082403.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16287",
          "name" : "16287",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0243",
          "name" : "ADV-2006-0243",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0323",
          "name" : "ADV-2006-0323",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24321",
          "name" : "oracle-january2006-update(24321)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Connection Manager component of Oracle Database server 8.1.7.4 and 9.0.1.5 has unspecified impact and attack vectors, as identified by Oracle Vuln# DB03."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database_server:8.1.7.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database_server:9.0.1.5:*:fips:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "acInsufInfo" : true,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-18T11:03Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0259",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "database_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.1.0.5",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18493",
          "name" : "18493",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18608",
          "name" : "18608",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1015499",
          "name" : "1015499",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/545804",
          "name" : "VU#545804",
          "refsource" : "CERT-VN",
          "tags" : [ "Patch", "US Government Resource" ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2006-082403.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2006-082403.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/22544",
          "name" : "22544",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16287",
          "name" : "16287",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0243",
          "name" : "ADV-2006-0243",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0323",
          "name" : "ADV-2006-0323",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24321",
          "name" : "oracle-january2006-update(24321)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple unspecified vulnerabilities in Oracle Database server 10.1.0.5 have unspecified impact and attack vectors, as identified by Oracle Vuln# (1) DB04 and (2) DB06 in the (a) Data Pump component; (3) DB10 in the (b) Net Listener component; and (4) DB16 in the (c) Oracle Text component.  NOTE: details are unavailable from Oracle, but they have not publicly disputed a claim by a reliable independent researcher that states that DB06 is SQL injection in the GENERATE_JOB_NAME, GET_WORKERSTATUSLIST1010, GET_PARAMVALUES1010, GET_DUMPFILESET1010, GET_JOBSTATUS1010, ATTACH, and ESTABLISH_REMOTE_CONTEXT functions in DBMS_DATAPUMP."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database_server:10.1.0.5:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "acInsufInfo" : true,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-18T11:03Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0260",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "database_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9.2.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.0.5",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18493",
          "name" : "18493",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18608",
          "name" : "18608",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1015499",
          "name" : "1015499",
          "refsource" : "SECTRACK",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/545804",
          "name" : "VU#545804",
          "refsource" : "CERT-VN",
          "tags" : [ "Third Party Advisory", "US Government Resource" ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2006-082403.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2006-082403.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/22543",
          "name" : "22543",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/22637",
          "name" : "22637",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/22643",
          "name" : "22643",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16287",
          "name" : "16287",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0243",
          "name" : "ADV-2006-0243",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0323",
          "name" : "ADV-2006-0323",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24321",
          "name" : "oracle-january2006-update(24321)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple unspecified vulnerabilities in Oracle Database server 9.2.0.7 and 10.1.0.5 have unspecified impact and attack vectors, as identified by Oracle Vuln# (1) DB05 in the (a) Data Pump component; (2) DB15 in the (b) Oracle Text component; (3) DB22 in the (c) Streams Apply component; (4) DB23 and (5) DB24 in the (d) Streams Capture component; and (6) DB26 in the (e) Streams Subcomponent.  NOTE: details are unavailable from Oracle, but they have not publicly disputed a claim by a reliable independent researcher that states that DB05 involves SQL injection in the (f) LONG2VARCHAR, LONG2VCMAX, LONG2VCNT, and LONG2CLOB functions in the DBMS_METADATA_UTIL package; (g) MAKE_FILTER, FETCH_VIEWS_ERROR, FETCH_FILTERS, FETCH_VIEWS, SET_FILTER_COMMON, DO_FILTER_SCRIPT, SET_TABLE_FILTERS, and MAKE_FILTER_TEXT functions in the DBMS_METADATA_INT package; and (h) GET_PREPOST_TABLE_ACT function in the DBMS_METADATA package."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database_server:9.2.0.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database_server:10.1.0.5:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "acInsufInfo" : true,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-18T11:03Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0261",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "database_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.1.7.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0.1.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.2.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.0.5",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18493",
          "name" : "18493",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18608",
          "name" : "18608",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1015499",
          "name" : "1015499",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/545804",
          "name" : "VU#545804",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2006-082403.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2006-082403.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.red-database-security.com/advisory/oracle_tde_wallet_password.html",
          "name" : "http://www.red-database-security.com/advisory/oracle_tde_wallet_password.html",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/422255/30/7430/threaded",
          "name" : "20060117 Oracle Database 10g Rel. 2 - Event 10053 logs TDE wallet password in cleartext",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16287",
          "name" : "16287",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0243",
          "name" : "ADV-2006-0243",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0323",
          "name" : "ADV-2006-0323",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24168",
          "name" : "oracle-masterkey-plaintext(24168)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24321",
          "name" : "oracle-january2006-update(24321)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple unspecified vulnerabilities in Oracle Database server 8.1.7.4, 9.0.1.5, 9.2.0.7, and 10.1.0.5 have unspecified impact and attack vectors, as identified by Oracle Vuln# (1) DB07 in the Dictionary component and (2) DB14 in the Oracle Label Security component.  NOTE: Oracle has not disputed reliable researcher claims that DB07 involves plaintext storage of the TDE wallet password in a trace file by event 10053."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database_server:8.1.7.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database_server:9.0.1.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database_server:9.0.1.5:*:fips:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database_server:9.2.0.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database_server:10.1.0.5:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "acInsufInfo" : true,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-18T11:03Z",
    "lastModifiedDate" : "2018-10-19T15:43Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0262",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "database_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.1.7.4",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "oracle10g",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "enterprise_10.1.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "personal_10.1.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "standard_10.1.0.4",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "oracle8i",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "enterprise_8.1.7.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "standard_8.1.7.4",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "oracle9i",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "enterprise_9.0.1.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "enterprise_9.0.1.5_fips",
                    "version_affected" : "="
                  }, {
                    "version_value" : "standard_9.2.0.6",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18493",
          "name" : "18493",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18608",
          "name" : "18608",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1015499",
          "name" : "1015499",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/545804",
          "name" : "VU#545804",
          "refsource" : "CERT-VN",
          "tags" : [ "Third Party Advisory", "US Government Resource" ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2006-082403.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2006-082403.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16287",
          "name" : "16287",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0243",
          "name" : "ADV-2006-0243",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0323",
          "name" : "ADV-2006-0323",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24321",
          "name" : "oracle-january2006-update(24321)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Net Foundation Layer component of Oracle Database server 8.1.7.4, 9.0.1.5, 9.0.1.5 FIPS, 9.2.0.6, and 10.1.0.4 has unspecified impact and attack vectors, as identified by Oracle Vuln# DB08."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database_server:8.1.7.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:oracle10g:enterprise_10.1.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:oracle10g:personal_10.1.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:oracle10g:standard_10.1.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:oracle8i:enterprise_8.1.7.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:oracle8i:standard_8.1.7.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:oracle9i:enterprise_9.0.1.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:oracle9i:enterprise_9.0.1.5_fips:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:oracle9i:standard_9.2.0.6:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "acInsufInfo" : true,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-18T11:03Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0263",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "database_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.1.7.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0.1.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.2.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.2.0.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18493",
          "name" : "18493",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18608",
          "name" : "18608",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1015499",
          "name" : "1015499",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/545804",
          "name" : "VU#545804",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/870172",
          "name" : "VU#870172",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2006-082403.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2006-082403.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/22547",
          "name" : "22547",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/22550",
          "name" : "22550",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/22551",
          "name" : "22551",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16287",
          "name" : "16287",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA06-018A.html",
          "name" : "TA06-018A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0243",
          "name" : "ADV-2006-0243",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0323",
          "name" : "ADV-2006-0323",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24321",
          "name" : "oracle-january2006-update(24321)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple unspecified vulnerabilities in Oracle Database server 8.1.7.4, 9.0.1.5, 9.0.1.5 FIPS, 9.2.0.7, 10.1.0.5, and 10.2.0.1 have unspecified impact and attack vectors, as identified by Oracle Vuln# (1) DB09 in the (a) Net Listener component; and (2) DB12 and (3) DB13 in the Network Communications (RPC) component."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database_server:8.1.7.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database_server:9.0.1.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database_server:9.0.1.5:*:fips:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database_server:9.2.0.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database_server:10.1.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database_server:10.2.0.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "acInsufInfo" : true,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-18T11:03Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0264",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ ]
        } ]
      },
      "references" : {
        "reference_data" : [ ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2006-0259.  Reason: This candidate is subsumed by CVE-2006-0259.  An error during initial CVE analysis used the wrong set of affected versions for \"DB10\". Notes: All CVE users should reference CVE-2006-0259 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ ]
    },
    "impact" : { },
    "publishedDate" : "2006-01-18T11:03Z",
    "lastModifiedDate" : "2008-09-10T19:57Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0265",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "database_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.1.7.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0.1.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.2.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.2.0.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18493",
          "name" : "18493",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18608",
          "name" : "18608",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1015499",
          "name" : "1015499",
          "refsource" : "SECTRACK",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/545804",
          "name" : "VU#545804",
          "refsource" : "CERT-VN",
          "tags" : [ "Third Party Advisory", "US Government Resource" ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2006-082403.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2006-082403.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/22555",
          "name" : "22555",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/22639",
          "name" : "22639",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/22640",
          "name" : "22640",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/22641",
          "name" : "22641",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/22642",
          "name" : "22642",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.red-database-security.com/advisory/oracle_cpu_jan_2006.html",
          "name" : "http://www.red-database-security.com/advisory/oracle_cpu_jan_2006.html",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16287",
          "name" : "16287",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0243",
          "name" : "ADV-2006-0243",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0323",
          "name" : "ADV-2006-0323",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24321",
          "name" : "oracle-january2006-update(24321)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple unspecified vulnerabilities in Oracle Database server 8.1.7.4, 9.0.1.5, 9.2.0.7, 10.1.0.5, and 10.2.0.1 have unspecified impact and attack vectors, as identified by Oracle Vuln# (1) DB17 in the Oracle Text component and (2) DB18 in the Program Interface Network component.  NOTE: details are unavailable from Oracle, but they have not publicly disputed a claim by a reliable independent researcher that states that DB17 involves SQL injection in the (a) VALIDATE_STATEMENT and BUILD_DML functions in CTXSYS.DRILOAD; (b) CLEAN_DML function in CTXSYS.DRIDML; (c) GET_ROWID function in CTXSYS.CTX_DOC; (d) BROWSE_WORDS function in CTXSYS.CTX_QUERY; and (e) ODCIINDEXTRUNCATE, ODCIINDEXDROP, and ODCIINDEXDELETE functions in CATINDEXMETHODS."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database_server:8.1.7.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database_server:9.0.1.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database_server:9.2.0.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database_server:10.1.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database_server:10.2.0.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "acInsufInfo" : true,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-18T11:03Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0266",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "database_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9.0.1.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.2.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.0.5",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18493",
          "name" : "18493",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18608",
          "name" : "18608",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1015499",
          "name" : "1015499",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/545804",
          "name" : "VU#545804",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2006-082403.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2006-082403.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16287",
          "name" : "16287",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0243",
          "name" : "ADV-2006-0243",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0323",
          "name" : "ADV-2006-0323",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24321",
          "name" : "oracle-january2006-update(24321)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Query Optimizer component of Oracle Database server 9.0.1.5, 9.2.0.7, and 10.1.0.5 has unspecified impact and attack vectors, as identified by Oracle Vuln# DB19."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database_server:9.0.1.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database_server:9.2.0.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database_server:10.1.0.5:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.0,
        "impactScore" : 10.0,
        "acInsufInfo" : true,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-18T11:03Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0267",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "database_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9.2.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.0.4",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18493",
          "name" : "18493",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18608",
          "name" : "18608",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1015499",
          "name" : "1015499",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/545804",
          "name" : "VU#545804",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2006-082403.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2006-082403.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16287",
          "name" : "16287",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0243",
          "name" : "ADV-2006-0243",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0323",
          "name" : "ADV-2006-0323",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24321",
          "name" : "oracle-january2006-update(24321)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Query Optimizer component of Oracle Database server 9.2.0.6 and 10.1.0.4 has unspecified impact and attack vectors, as identified by Oracle Vuln# DB20."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database_server:9.2.0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database_server:10.1.0.4:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.0,
        "impactScore" : 10.0,
        "acInsufInfo" : true,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-18T11:03Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0268",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "database_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9.0.1.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.2.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.0.4",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18493",
          "name" : "18493",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18608",
          "name" : "18608",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1015499",
          "name" : "1015499",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/545804",
          "name" : "VU#545804",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2006-082403.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2006-082403.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16287",
          "name" : "16287",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0243",
          "name" : "ADV-2006-0243",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0323",
          "name" : "ADV-2006-0323",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24321",
          "name" : "oracle-january2006-update(24321)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Security component of Oracle Database server 9.0.1.5, 9.0.1.5 FIPS, 9.2.0.6, and 10.1.0.4 has unspecified impact and attack vectors, as identified by Oracle Vuln# DB21."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database_server:9.0.1.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database_server:9.0.1.5:*:fips:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database_server:9.2.0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database_server:10.1.0.4:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.0,
        "impactScore" : 10.0,
        "acInsufInfo" : true,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-18T11:03Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0269",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "oracle10g",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "standard_10.1.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "standard_10.2.0.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          }, {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18493",
          "name" : "18493",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18608",
          "name" : "18608",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1015499",
          "name" : "1015499",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/545804",
          "name" : "VU#545804",
          "refsource" : "CERT-VN",
          "tags" : [ "Third Party Advisory", "US Government Resource" ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2006-082403.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2006-082403.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/22563",
          "name" : "22563",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.red-database-security.com/advisory/oracle_cpu_jan_2006.html",
          "name" : "http://www.red-database-security.com/advisory/oracle_cpu_jan_2006.html",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16287",
          "name" : "16287",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0243",
          "name" : "ADV-2006-0243",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0323",
          "name" : "ADV-2006-0323",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24321",
          "name" : "oracle-january2006-update(24321)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Streams Capture component of Oracle Database server 10.1.0.5 and 10.2.0.1 has unspecified impact and attack vectors, as identified by Oracle Vuln# DB25.  NOTE: details are unavailable from Oracle, but they have not publicly disputed a claim by a reliable independent researcher that states that the problem is SQL injection in the SET_DIRECTORY_ROOT function in the DBMS_CDC_PUBLISH package."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:oracle10g:standard_10.1.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:oracle10g:standard_10.2.0.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:P/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.5
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.0,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-18T11:03Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0270",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "database_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.2.0.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          }, {
            "lang" : "en",
            "value" : "CWE-310"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18493",
          "name" : "18493",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18608",
          "name" : "18608",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1015499",
          "name" : "1015499",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/545804",
          "name" : "VU#545804",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2006-082403.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2006-082403.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.red-database-security.com/advisory/oracle_tde_unencrypted_sga.html",
          "name" : "http://www.red-database-security.com/advisory/oracle_tde_unencrypted_sga.html",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/422262/30/7400/threaded",
          "name" : "20060117 Oracle Database 10g Rel. 2- Transparent Data Encryption plaintext masterkey in SGA",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16287",
          "name" : "16287",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0243",
          "name" : "ADV-2006-0243",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0323",
          "name" : "ADV-2006-0323",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24186",
          "name" : "oracle-sga-masterkey-plaintext(24186)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24321",
          "name" : "oracle-january2006-update(24321)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Transparent Data Encryption (TDE) Wallet component of Oracle Database server 10.2.0.1 has unspecified impact and attack vectors, as identified by Oracle Vuln# DB27.  NOTE: Oracle has not disputed a reliable researcher report that TDA stores the master key without encryption, which allows local users to obtain the key via the SGA."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database_server:10.2.0.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-18T11:03Z",
    "lastModifiedDate" : "2018-10-19T15:43Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0271",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "database_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.1.7.4",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "oracle10g",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "enterprise_10.1.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "personal_10.1.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "standard_10.1.0.4",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "oracle8i",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "enterprise_8.1.7.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "standard_8.1.7.4",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "oracle9i",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "enterprise_9.0.1.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "standard_9.2.0.7",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18493",
          "name" : "18493",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18608",
          "name" : "18608",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1015499",
          "name" : "1015499",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/545804",
          "name" : "VU#545804",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2006-082403.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2006-082403.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/22566",
          "name" : "22566",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.red-database-security.com/advisory/oracle_cpu_jan_2006.html",
          "name" : "http://www.red-database-security.com/advisory/oracle_cpu_jan_2006.html",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16287",
          "name" : "16287",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0243",
          "name" : "ADV-2006-0243",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0323",
          "name" : "ADV-2006-0323",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24321",
          "name" : "oracle-january2006-update(24321)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Upgrade & Downgrade component of Oracle Database server 8.1.7.4, 9.0.1.5, 9.2.0.7, and 10.1.0.4 has unspecified impact and attack vectors, as identified by Oracle Vuln# DB28.  NOTE: details are unavailable from Oracle, but they have not publicly disputed a claim by a reliable independent researcher that states that the problem is SQL injection in the DBMS_REGISTRY package in certain parameters to the (1) IS_COMPONENT, (2) GET_COMP_OPTION, (3) DISABLE_DDL_TRIGGERS, (4) SCRIPT_EXISTS, (5) COMP_PATH, (6) GATHER_STATS, (7) NOTHING_SCRIPT, and (8) VALIDATE_COMPONENTS functions."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database_server:8.1.7.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:oracle10g:enterprise_10.1.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:oracle10g:personal_10.1.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:oracle10g:standard_10.1.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:oracle8i:enterprise_8.1.7.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:oracle8i:standard_8.1.7.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:oracle9i:enterprise_9.0.1.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:oracle9i:standard_9.2.0.7:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "acInsufInfo" : true,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-18T11:03Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0272",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "oracle10g",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "enterprise_10.1.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "personal_10.1.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "standard_10.1.0.4",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "oracle9i",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "standard_9.2.0.7",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://archives.neohapsis.com/archives/fulldisclosure/2006-01/0893.html",
          "name" : "20060126 [Argeniss] Oracle Database Buffer overflows vulnerabilities in public procedures of XDB.DBMS_XMLSCHEMA{_INT}",
          "refsource" : "FULLDISC",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18493",
          "name" : "18493",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18608",
          "name" : "18608",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1015499",
          "name" : "1015499",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.argeniss.com/research/ARGENISS-ADV-010601.txt",
          "name" : "http://www.argeniss.com/research/ARGENISS-ADV-010601.txt",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.integrigy.com/info/IntegrigySecurityAnalysis-CPU0106.pdf",
          "name" : "http://www.integrigy.com/info/IntegrigySecurityAnalysis-CPU0106.pdf",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/545804",
          "name" : "VU#545804",
          "refsource" : "CERT-VN",
          "tags" : [ "Third Party Advisory", "US Government Resource" ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/891644",
          "name" : "VU#891644",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2006-082403.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2006-082403.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.red-database-security.com/advisory/oracle_cpu_jan_2006.html",
          "name" : "http://www.red-database-security.com/advisory/oracle_cpu_jan_2006.html",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16287",
          "name" : "16287",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA06-018A.html",
          "name" : "TA06-018A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0243",
          "name" : "ADV-2006-0243",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0323",
          "name" : "ADV-2006-0323",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24321",
          "name" : "oracle-january2006-update(24321)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24376",
          "name" : "oracle-xdbdbmx-xmlschema-bo(24376)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the XML Database component of Oracle Database server 9.2.0.7 and 10.1.0.4 has unspecified impact and attack vectors, as identified by Oracle Vuln# DB29.  NOTE: based on mutual credits by the relevant sources, it is highly likely that this issue is a buffer overflow in the (a) DBMS_XMLSCHEMA and (b) DBMS_XMLSCHEMA_INT packages, as exploitable via long arguments to (1) XDB.DBMS_XMLSCHEMA.GENERATESCHEMA or (2) XDB.DBMS_XMLSCHEMA.GENERATESCHEMAS."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:oracle10g:enterprise_10.1.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:oracle10g:personal_10.1.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:oracle10g:standard_10.1.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:oracle9i:standard_9.2.0.7:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.0,
        "impactScore" : 10.0,
        "acInsufInfo" : true,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-18T11:03Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0273",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "application_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9.0.4.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.2.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18493",
          "name" : "18493",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18608",
          "name" : "18608",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1015499",
          "name" : "1015499",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/545804",
          "name" : "VU#545804",
          "refsource" : "CERT-VN",
          "tags" : [ "Third Party Advisory", "US Government Resource" ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2006-082403.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2006-082403.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16287",
          "name" : "16287",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0243",
          "name" : "ADV-2006-0243",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0323",
          "name" : "ADV-2006-0323",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24321",
          "name" : "oracle-january2006-update(24321)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Portal component of Oracle Application Server 9.0.4.2 and 10.1.2.0 has unspecified impact and attack vectors, as identified by Oracle Vuln# AS01."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_server:9.0.4.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_server:10.1.2.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "acInsufInfo" : true,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-18T11:03Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0274",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "application_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9.0.4.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.2.0.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18493",
          "name" : "18493",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18608",
          "name" : "18608",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1015499",
          "name" : "1015499",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/545804",
          "name" : "VU#545804",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2006-082403.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2006-082403.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16287",
          "name" : "16287",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0243",
          "name" : "ADV-2006-0243",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0323",
          "name" : "ADV-2006-0323",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24321",
          "name" : "oracle-january2006-update(24321)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Oracle Reports Developer component of Oracle Application Server 9.0.4.2 and 10.1.2.0.2 has unspecified impact and attack vectors, as identified by Oracle Vuln# REP03."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_server:9.0.4.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_server:10.1.2.0.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "acInsufInfo" : true,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-18T11:03Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0275",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "application_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9.0.4.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18493",
          "name" : "18493",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18608",
          "name" : "18608",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1015499",
          "name" : "1015499",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/545804",
          "name" : "VU#545804",
          "refsource" : "CERT-VN",
          "tags" : [ "Third Party Advisory", "US Government Resource" ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2006-082403.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2006-082403.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.red-database-security.com/advisory/oracle_reports_read_any_xml_file.html",
          "name" : "http://www.red-database-security.com/advisory/oracle_reports_read_any_xml_file.html",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/422261/30/7430/threaded",
          "name" : "20060117 Oracle Reports - Read parts of files via customize(fixed after 875 days)",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16287",
          "name" : "16287",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0243",
          "name" : "ADV-2006-0243",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0323",
          "name" : "ADV-2006-0323",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24321",
          "name" : "oracle-january2006-update(24321)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Oracle Reports Developer component of Oracle Application Server 9.0.4.2 has unspecified impact and attack vectors, as identified by Oracle Vuln# REP04.  NOTE: Oracle has not disputed reliable researcher claims that this issue is related to directory traversal that allows reading of portions of arbitrary XML files via the customize parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_server:9.0.4.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-18T11:03Z",
    "lastModifiedDate" : "2018-10-19T15:43Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0276",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "collaboration_suite",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9.0.4.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18493",
          "name" : "18493",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18608",
          "name" : "18608",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1015499",
          "name" : "1015499",
          "refsource" : "SECTRACK",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/545804",
          "name" : "VU#545804",
          "refsource" : "CERT-VN",
          "tags" : [ "Third Party Advisory", "US Government Resource" ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2006-082403.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2006-082403.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16287",
          "name" : "16287",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0243",
          "name" : "ADV-2006-0243",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0323",
          "name" : "ADV-2006-0323",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24321",
          "name" : "oracle-january2006-update(24321)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple unspecified vulnerabilities in Oracle Collaboration Suite Release 2, version 9.0.4.2 (Oracle9i) have unspecified impact and attack vectors, as identified by Oracle Vuln# (1) OCS01, 2) OCS02, 3) OCS03, 4) OCS04, 5) OCS05, 6) OCS06, 7) OCS07, (8) OCS08, and (9) OCS09 in the (a) Email Server component; 10) OCS10 (and (11) OCS11 in the (b) Oracle Collaboration Suite Wireless & Voice (component; 12) OCS12 and (13) OCS13 in the (c) Oracle Content (Management SDK component; 14) OCS14 and (15) OCS15 in the (d) Oracle (Content Services component."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:collaboration_suite:9.0.4.2:r2:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "acInsufInfo" : true,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-18T11:03Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0277",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "e-business_suite",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11.5.10",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18493",
          "name" : "18493",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18608",
          "name" : "18608",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1015499",
          "name" : "1015499",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/545804",
          "name" : "VU#545804",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2006-082403.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2006-082403.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16287",
          "name" : "16287",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0243",
          "name" : "ADV-2006-0243",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0323",
          "name" : "ADV-2006-0323",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24321",
          "name" : "oracle-january2006-update(24321)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple unspecified vulnerabilities in Oracle E-Business Suite and Applications 11.5.10 have unspecified impact and attack vectors, as identified by Oracle Vuln# (1) APPS01 in the (a) Application Install component; (2) APPS07 in the (b) Oracle Applications Framework component; (3) APPS08, (4) APPS09, (5) APPS10, and (6) APPS11 in the (c) Oracle Applications Technology Stack component; (7) APPS12 in the (d) Oracle Human Resources component; (8) APPS15 and (9) APPS16 in the (e) Oracle Marketing component; (10) APPS17 in the (f) Marketing Encyclopedia System component; (11) APPS18 in the (g) Oracle Trade Management component; and (12) APPS19 in the (h) Oracle Web Applications Desktop Integration component."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:e-business_suite:11.5.10:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "acInsufInfo" : true,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-18T11:03Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0278",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "e-business_suite",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11.5.9",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18493",
          "name" : "18493",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18608",
          "name" : "18608",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1015499",
          "name" : "1015499",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/545804",
          "name" : "VU#545804",
          "refsource" : "CERT-VN",
          "tags" : [ "Third Party Advisory", "US Government Resource" ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2006-082403.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2006-082403.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16287",
          "name" : "16287",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0243",
          "name" : "ADV-2006-0243",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0323",
          "name" : "ADV-2006-0323",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24321",
          "name" : "oracle-january2006-update(24321)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple unspecified vulnerabilities in Oracle E-Business Suite and Applications 11.5.9 have unspecified impact and attack vectors, as identified by Oracle Vuln# (1) APPS02 in the (a) CRM Technical Foundation component; (2) APPS03 in the (b) iProcurement component; and (3) APPS04, (4) APPS05, and (5) APPS06 in the Oracle Application Object Library component."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:e-business_suite:11.5.9:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "acInsufInfo" : true,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-18T11:03Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0279",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "e-business_suite",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18493",
          "name" : "18493",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18608",
          "name" : "18608",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1015499",
          "name" : "1015499",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/545804",
          "name" : "VU#545804",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2006-082403.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2006-082403.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16287",
          "name" : "16287",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0243",
          "name" : "ADV-2006-0243",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0323",
          "name" : "ADV-2006-0323",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24321",
          "name" : "oracle-january2006-update(24321)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple unspecified vulnerabilities in Oracle E-Business Suite and Applications 4.3 have unspecified impact and attack vectors, as identified by Oracle Vuln# (1) APPS13 and (2) APPS14 in the Oracle iLearning component."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:e-business_suite:4.3:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "acInsufInfo" : true,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-18T11:03Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0280",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "peoplesoft_enterprise_portal",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.9",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18493",
          "name" : "18493",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18608",
          "name" : "18608",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1015499",
          "name" : "1015499",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/545804",
          "name" : "VU#545804",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2006-082403.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2006-082403.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16287",
          "name" : "16287",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0243",
          "name" : "ADV-2006-0243",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0323",
          "name" : "ADV-2006-0323",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24321",
          "name" : "oracle-january2006-update(24321)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in Oracle PeopleSoft Enterprise Portal 8.4 Bundle 15, 8.8 Bundle 10, and 8.9 Bundle 2 has unspecified impact and attack vectors, as identified by Oracle Vuln# PSE01."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:peoplesoft_enterprise_portal:8.4:bundle15:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:peoplesoft_enterprise_portal:8.8:bundle10:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:peoplesoft_enterprise_portal:8.9:bundle2:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "acInsufInfo" : true,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-18T11:03Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0281",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "enterpriseone",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.95.f1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "sp23_l1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18493",
          "name" : "18493",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18608",
          "name" : "18608",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1015499",
          "name" : "1015499",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/545804",
          "name" : "VU#545804",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2006-082403.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2006-082403.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16287",
          "name" : "16287",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0243",
          "name" : "ADV-2006-0243",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0323",
          "name" : "ADV-2006-0323",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24321",
          "name" : "oracle-january2006-update(24321)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in Oracle JD Edwards HTML Server 8.95.F1 SP23_L1 has unspecified impact and attack vectors, as identified by Oracle Vuln# JDE01."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:enterpriseone:8.95.f1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:enterpriseone:sp23_l1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "acInsufInfo" : true,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-18T11:03Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0282",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "application_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0.2.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0.4.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.2.0.2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "collaboration_suite",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9.0.4.2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "database_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.1.7.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0.1.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.2.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.0.5",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18493",
          "name" : "18493",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18608",
          "name" : "18608",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1015499",
          "name" : "1015499",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/545804",
          "name" : "VU#545804",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2006-082403.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2006-082403.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16287",
          "name" : "16287",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0243",
          "name" : "ADV-2006-0243",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0323",
          "name" : "ADV-2006-0323",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24321",
          "name" : "oracle-january2006-update(24321)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in Oracle Database Server 8.1.7.4, 9.0.1.5, 9.0.1.5 FIPS, 9.2.0.7, and 10.1.0.5, Application Server 1.0.2.2, 9.0.4.2, and 10.1.2.0.2, and Collaboration Suite Release 2, version 9.0.4.2 (Oracle9i) has unspecified impact and attack vectors, as identified by Oracle Vuln# DBC01 in the Protocol Support component."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_server:1.0.2.2:r1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_server:9.0.4.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_server:10.1.2.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_server:10.1.2.0.2:r2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:collaboration_suite:9.0.4.2:r2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database_server:8.1.7.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database_server:9.0.1.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database_server:9.0.1.5:*:fips:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database_server:9.2.0.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database_server:10.1.0.5:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "acInsufInfo" : true,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-18T11:03Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0283",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "application_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.1.2.0.2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "collaboration_suite",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9.0.4.2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "database_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.1.0.4.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18493",
          "name" : "18493",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18608",
          "name" : "18608",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1015499",
          "name" : "1015499",
          "refsource" : "SECTRACK",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/545804",
          "name" : "VU#545804",
          "refsource" : "CERT-VN",
          "tags" : [ "Third Party Advisory", "US Government Resource" ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2006-082403.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2006-082403.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16287",
          "name" : "16287",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0243",
          "name" : "ADV-2006-0243",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0323",
          "name" : "ADV-2006-0323",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24321",
          "name" : "oracle-january2006-update(24321)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in Oracle Database Server 10.1.0.4.2, Application Server 10.1.2.0.2, and Collaboration Suite Release 2, version 9.0.4.2 (Oracle9i) has unspecified impact and attack vectors, as identified by Oracle Vuln# DBC02 in the Reorganize Objects & Convert Tablespace component."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_server:10.1.2.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:collaboration_suite:9.0.4.2:r2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database_server:10.1.0.4.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "acInsufInfo" : true,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-18T11:03Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0284",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "application_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9.0.4.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.2.0.2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "e-business_suite",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11.5.10",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18493",
          "name" : "18493",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18608",
          "name" : "18608",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1015499",
          "name" : "1015499",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/545804",
          "name" : "VU#545804",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2006-082403.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2006-082403.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16287",
          "name" : "16287",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0243",
          "name" : "ADV-2006-0243",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0323",
          "name" : "ADV-2006-0323",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24321",
          "name" : "oracle-january2006-update(24321)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple unspecified vulnerabilities in Oracle Application Server 9.0.4.2 and 10.1.2.0.2, and E-Business Suite and Applications 11.5.10, have unspecified impact and attack vectors, as identified by Oracle Vuln# (1) FORM01 and (2) FORM02 in the Oracle Forms component."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_server:9.0.4.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_server:10.1.2.0.2:r2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:e-business_suite:11.5.10:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "acInsufInfo" : true,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-18T11:03Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0285",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "application_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0.2.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0.4.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.2.0.2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "database_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.1.7.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0.1.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.2.0.7",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18493",
          "name" : "18493",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18608",
          "name" : "18608",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1015499",
          "name" : "1015499",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/545804",
          "name" : "VU#545804",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2006-082403.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2006-082403.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16287",
          "name" : "16287",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0243",
          "name" : "ADV-2006-0243",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0323",
          "name" : "ADV-2006-0323",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24321",
          "name" : "oracle-january2006-update(24321)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Java Net component of Oracle Database Server 8.1.7.4, 9.0.1.5, 9.0.1.5 FIPS, 9.2.0.7, and 10.1.0.4, and Application Server 1.0.2.2, 9.0.4.2, and 10.1.2.0.2, has unspecified impact and attack vectors, as identified by Oracle Vuln# JN01."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_server:1.0.2.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_server:9.0.4.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_server:10.1.2.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database_server:8.1.7.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database_server:9.0.1.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database_server:9.0.1.5:*:fips:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database_server:9.2.0.7:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "acInsufInfo" : true,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-18T11:03Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0286",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "application_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0.2.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0.4.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.2.0.2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "database_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9.0.1.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.2.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.0.5",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18493",
          "name" : "18493",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18608",
          "name" : "18608",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1015499",
          "name" : "1015499",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/545804",
          "name" : "VU#545804",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2006-082403.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2006-082403.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16287",
          "name" : "16287",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0243",
          "name" : "ADV-2006-0243",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0323",
          "name" : "ADV-2006-0323",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24321",
          "name" : "oracle-january2006-update(24321)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Oracle HTTP Server component of Oracle Database Server 9.0.1.5, 9.0.1.5 FIPS, 9.2.0.7, and 10.1.0.5, and Application Server 1.0.2.2, 9.0.4.2, and 10.1.2.0.2, has unspecified impact and attack vectors, as identified by Oracle Vuln# OHS01."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_server:1.0.2.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_server:9.0.4.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_server:10.1.2.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database_server:9.0.1.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database_server:9.0.1.5:*:fips:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database_server:9.2.0.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database_server:10.1.0.5:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "acInsufInfo" : true,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-18T11:03Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0287",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "application_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.1.2.0.2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "database_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.1.0.5",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18493",
          "name" : "18493",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18608",
          "name" : "18608",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1015499",
          "name" : "1015499",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/545804",
          "name" : "VU#545804",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2006-082403.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2006-082403.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16287",
          "name" : "16287",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0243",
          "name" : "ADV-2006-0243",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0323",
          "name" : "ADV-2006-0323",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24321",
          "name" : "oracle-january2006-update(24321)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Oracle HTTP Server component of Oracle Database Server 10.1.0.5 and Application Server 10.1.2.0.2 has unspecified impact and attack vectors, as identified by Oracle Vuln# OHS02."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_server:10.1.2.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database_server:10.1.0.5:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "acInsufInfo" : true,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-18T11:03Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0288",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "application_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9.0.4.1",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "e-business_suite",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11.5.10",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18493",
          "name" : "18493",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18608",
          "name" : "18608",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1015499",
          "name" : "1015499",
          "refsource" : "SECTRACK",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/545804",
          "name" : "VU#545804",
          "refsource" : "CERT-VN",
          "tags" : [ "Third Party Advisory", "US Government Resource" ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2006-082403.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2006-082403.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16287",
          "name" : "16287",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0243",
          "name" : "ADV-2006-0243",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0323",
          "name" : "ADV-2006-0323",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24321",
          "name" : "oracle-january2006-update(24321)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple unspecified vulnerabilities in the Oracle Reports Developer component of Oracle Application Server 9.0.4.1 and E-Business Suite and Applications 11.5.10 have unspecified impact and attack vectors, as identified by Oracle Vuln# (1) REP01 and (2) REP02."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_server:9.0.4.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:e-business_suite:11.5.10:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "acInsufInfo" : true,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-18T11:03Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0289",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "application_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.0.8.26_ps17",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "e-business_suite",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11.5.10",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18493",
          "name" : "18493",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18608",
          "name" : "18608",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1015499",
          "name" : "1015499",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/545804",
          "name" : "VU#545804",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2006-082403.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2006-082403.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.red-database-security.com/advisory/oracle_reports_overwrite_any_file.html",
          "name" : "http://www.red-database-security.com/advisory/oracle_reports_overwrite_any_file.html",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.red-database-security.com/advisory/oracle_reports_read_any_file.html",
          "name" : "http://www.red-database-security.com/advisory/oracle_reports_read_any_file.html",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/422256/30/7430/threaded",
          "name" : "20060117 Oracle Reports - Read parts of files via desname (fixed after 874 days)",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/422257/30/7430/threaded",
          "name" : "20060117 Oracle Reports - Overwrite any application server file via desname (fixed after 889 days)",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16287",
          "name" : "16287",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0243",
          "name" : "ADV-2006-0243",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0323",
          "name" : "ADV-2006-0323",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24321",
          "name" : "oracle-january2006-update(24321)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple unspecified vulnerabilities in Oracle Application Server 6.0.8.26(PS17) and E-Business Suite and Applications 11.5.10 have unspecified impact and attack vectors, as identified by Oracle Vuln# (1) REP05 and (2) REP06 in the Oracle Reports Developer component. NOTE: Oracle has not disputed reliable researcher claims that REP05 is the same as CVE-2005-2378 and REP06 is the same as CVE-2005-2371, both of which involve directory traversal."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_server:6.0.8.26_ps17:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:e-business_suite:11.5.10:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-18T11:03Z",
    "lastModifiedDate" : "2018-10-19T15:43Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0290",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "application_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9.0.4.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.2.1",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "collaboration_suite",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9.0.4.2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "database_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9.2.0.7",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "e-business_suite",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11.5.10",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18493",
          "name" : "18493",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18608",
          "name" : "18608",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1015499",
          "name" : "1015499",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/545804",
          "name" : "VU#545804",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2006-082403.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2006-082403.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16287",
          "name" : "16287",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0243",
          "name" : "ADV-2006-0243",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0323",
          "name" : "ADV-2006-0323",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24321",
          "name" : "oracle-january2006-update(24321)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in Oracle Database Server 9.2.0.7, Application Server 9.0.4.2 and 10.1.2.1, Collaboration Suite Release 2, version 9.0.4.2 (Oracle9i), and E-Business Suite and Applications 11.5.10 has unspecified impact and attack vectors, as identified by Oracle Vuln# WF01 in the Oracle Workflow Cartridge component."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_server:9.0.4.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_server:10.1.2.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:collaboration_suite:9.0.4.2:r2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database_server:9.2.0.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:e-business_suite:11.5.10:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "acInsufInfo" : true,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-18T11:03Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0291",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "application_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9.0.4.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.2.1.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "collaboration_suite",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9.0.4.2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "database_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.2.0.1",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "e-business_suite",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11.5.10",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18493",
          "name" : "18493",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18608",
          "name" : "18608",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1015499",
          "name" : "1015499",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/545804",
          "name" : "VU#545804",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2006-082403.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2006-082403.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16287",
          "name" : "16287",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0243",
          "name" : "ADV-2006-0243",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0323",
          "name" : "ADV-2006-0323",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24321",
          "name" : "oracle-january2006-update(24321)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple unspecified vulnerabilities in Oracle Database Server 10.2.0.1, Application Server 9.0.4.2 and 10.1.2.1, Collaboration Suite Release 2, version 9.0.4.2 (Oracle9i), and E-Business Suite and Applications 11.5.10 have unspecified impact and attack vectors, as identified by Oracle Vuln# (1) WF02 and (2) WF03 in the Oracle Workflow Cartridge component."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_server:9.0.4.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_server:10.1.2.1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:collaboration_suite:9.0.4.2:r2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database_server:10.2.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:e-business_suite:11.5.10:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "acInsufInfo" : true,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-18T11:03Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0292",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "mozilla",
            "product" : {
              "product_data" : [ {
                "product_name" : "firefox",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.9.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.9.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.9.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.10.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "mozilla",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2006.26/SCOSA-2006.26.txt",
          "name" : "SCOSA-2006.26",
          "refsource" : "SCO",
          "tags" : [ ]
        }, {
          "url" : "ftp://patches.sgi.com/support/free/security/advisories/20060201-01-U",
          "name" : "20060201-01-U",
          "refsource" : "SGI",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18700",
          "name" : "18700",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18703",
          "name" : "18703",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18704",
          "name" : "18704",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18705",
          "name" : "18705",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18706",
          "name" : "18706",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18708",
          "name" : "18708",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18709",
          "name" : "18709",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/19230",
          "name" : "19230",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/19746",
          "name" : "19746",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/19759",
          "name" : "19759",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/19780",
          "name" : "19780",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/19821",
          "name" : "19821",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/19823",
          "name" : "19823",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/19852",
          "name" : "19852",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/19862",
          "name" : "19862",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/19863",
          "name" : "19863",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/19902",
          "name" : "19902",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/19941",
          "name" : "19941",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/19950",
          "name" : "19950",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/20051",
          "name" : "20051",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/21033",
          "name" : "21033",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/21622",
          "name" : "21622",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/22065",
          "name" : "22065",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1015570",
          "name" : "1015570",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://sunsolve.sun.com/search/document.do?assetkey=1-26-102550-1",
          "name" : "102550",
          "refsource" : "SUNALERT",
          "tags" : [ ]
        }, {
          "url" : "http://sunsolve.sun.com/search/document.do?assetkey=1-26-228526-1",
          "name" : "228526",
          "refsource" : "SUNALERT",
          "tags" : [ ]
        }, {
          "url" : "http://support.avaya.com/elmodocs2/security/ASA-2006-205.htm",
          "name" : "http://support.avaya.com/elmodocs2/security/ASA-2006-205.htm",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2006/dsa-1044",
          "name" : "DSA-1044",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2006/dsa-1046",
          "name" : "DSA-1046",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2006/dsa-1051",
          "name" : "DSA-1051",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.gentoo.org/security/en/glsa/glsa-200604-12.xml",
          "name" : "GLSA-200604-12",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://www.gentoo.org/security/en/glsa/glsa-200604-18.xml",
          "name" : "GLSA-200604-18",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://www.gentoo.org/security/en/glsa/glsa-200605-09.xml",
          "name" : "GLSA-200605-09",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDKSA-2006:036",
          "name" : "MDKSA-2006:036",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDKSA-2006:037",
          "name" : "MDKSA-2006:037",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDKSA-2006:078",
          "name" : "MDKSA-2006:078",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.mozilla.org/security/announce/2006/mfsa2006-01.html",
          "name" : "http://www.mozilla.org/security/announce/2006/mfsa2006-01.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.novell.com/linux/security/advisories/2006_04_25.html",
          "name" : "SUSE-SA:2006:022",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/archives/fedora-announce-list/2006-February/msg00005.html",
          "name" : "FEDORA-2006-075",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/archives/fedora-announce-list/2006-February/msg00006.html",
          "name" : "FEDORA-2006-076",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2006-0199.html",
          "name" : "RHSA-2006:0199",
          "refsource" : "REDHAT",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2006-0200.html",
          "name" : "RHSA-2006:0200",
          "refsource" : "REDHAT",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2006-0330.html",
          "name" : "RHSA-2006:0330",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/425975/100/0/threaded",
          "name" : "FLSA:180036-1",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/425978/100/0/threaded",
          "name" : "FLSA-2006:180036-2",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/438730/100/0/threaded",
          "name" : "HPSBUX02122",
          "refsource" : "HP",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/446657/100/200/threaded",
          "name" : "SSRT061236",
          "refsource" : "HP",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16476",
          "name" : "16476",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0413",
          "name" : "ADV-2006-0413",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/3391",
          "name" : "ADV-2006-3391",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/3749",
          "name" : "ADV-2006-3749",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://bugzilla.mozilla.org/show_bug.cgi?id=316885",
          "name" : "https://bugzilla.mozilla.org/show_bug.cgi?id=316885",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24430",
          "name" : "mozilla-javascript-memory-corruption(24430)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10016",
          "name" : "oval:org.mitre.oval:def:10016",
          "refsource" : "OVAL",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A670",
          "name" : "oval:org.mitre.oval:def:670",
          "refsource" : "OVAL",
          "tags" : [ ]
        }, {
          "url" : "https://usn.ubuntu.com/271-1/",
          "name" : "USN-271-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "https://usn.ubuntu.com/275-1/",
          "name" : "USN-275-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "https://usn.ubuntu.com/276-1/",
          "name" : "USN-276-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The Javascript interpreter (jsinterp.c) in Mozilla and Firefox before 1.5.1 does not properly dereference objects, which allows remote attackers to cause a denial of service (crash) or execute arbitrary code via unknown attack vectors related to garbage collection."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:0.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:0.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:0.9:rc:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:0.9.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:0.9.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:0.9.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:0.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:0.10.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.0.6:*:linux:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.0.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.5:beta1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:mozilla:1.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:mozilla:1.4.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:mozilla:1.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:mozilla:1.5:alpha:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:mozilla:1.5:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:mozilla:1.5:rc2:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-02T20:06Z",
    "lastModifiedDate" : "2018-10-19T15:43Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0293",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "mozilla",
            "product" : {
              "product_data" : [ {
                "product_name" : "firefox",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.5",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18700",
          "name" : "18700",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18704",
          "name" : "18704",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/19862",
          "name" : "19862",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/19863",
          "name" : "19863",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/19902",
          "name" : "19902",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/19941",
          "name" : "19941",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/21622",
          "name" : "21622",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/22065",
          "name" : "22065",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1015570",
          "name" : "1015570",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://sunsolve.sun.com/search/document.do?assetkey=1-26-102550-1",
          "name" : "102550",
          "refsource" : "SUNALERT",
          "tags" : [ ]
        }, {
          "url" : "http://sunsolve.sun.com/search/document.do?assetkey=1-26-228526-1",
          "name" : "228526",
          "refsource" : "SUNALERT",
          "tags" : [ ]
        }, {
          "url" : "http://support.avaya.com/elmodocs2/security/ASA-2006-205.htm",
          "name" : "http://support.avaya.com/elmodocs2/security/ASA-2006-205.htm",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2006/dsa-1044",
          "name" : "DSA-1044",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2006/dsa-1046",
          "name" : "DSA-1046",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2006/dsa-1051",
          "name" : "DSA-1051",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.gentoo.org/security/en/glsa/glsa-200604-18.xml",
          "name" : "GLSA-200604-18",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://www.mozilla.org/security/announce/2006/mfsa2006-01.html",
          "name" : "http://www.mozilla.org/security/announce/2006/mfsa2006-01.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/438730/100/0/threaded",
          "name" : "HPSBUX02122",
          "refsource" : "HP",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/446657/100/200/threaded",
          "name" : "SSRT061236",
          "refsource" : "HP",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16476",
          "name" : "16476",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0413",
          "name" : "ADV-2006-0413",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/3391",
          "name" : "ADV-2006-3391",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/3749",
          "name" : "ADV-2006-3749",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://bugzilla.mozilla.org/show_bug.cgi?id=322045",
          "name" : "https://bugzilla.mozilla.org/show_bug.cgi?id=322045",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24430",
          "name" : "mozilla-javascript-memory-corruption(24430)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/42654",
          "name" : "firefox-function-allocation-code-execution(42654)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1494",
          "name" : "oval:org.mitre.oval:def:1494",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The function allocation code (js_NewFunction in jsfun.c) in Firefox 1.5 allows attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code via user-defined methods that trigger garbage collection in a way that operates on freed objects."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.5:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-02T20:06Z",
    "lastModifiedDate" : "2018-10-19T15:43Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0294",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "mozilla",
            "product" : {
              "product_data" : [ {
                "product_name" : "firefox",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.9.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.9.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.9.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.10.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "seamonkey",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "thunderbird",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.5",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18700",
          "name" : "18700",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18704",
          "name" : "18704",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/22065",
          "name" : "22065",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1015570",
          "name" : "1015570",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.mozilla.org/security/announce/2006/mfsa2006-02.html",
          "name" : "http://www.mozilla.org/security/announce/2006/mfsa2006-02.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/446657/100/200/threaded",
          "name" : "SSRT061236",
          "refsource" : "HP",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16476",
          "name" : "16476",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0413",
          "name" : "ADV-2006-0413",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/3749",
          "name" : "ADV-2006-3749",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://bugzilla.mozilla.org/show_bug.cgi?id=317934",
          "name" : "https://bugzilla.mozilla.org/show_bug.cgi?id=317934",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24431",
          "name" : "mozilla-element-change-memory-corruption(24431)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1514",
          "name" : "oval:org.mitre.oval:def:1514",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Mozilla Firefox before 1.5.0.1, Thunderbird 1.5 if running Javascript in mail, and SeaMonkey before 1.0 allow remote attackers to execute arbitrary code by changing an element's style from position:relative to position:static, which causes Gecko to operate on freed memory."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:0.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:0.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:0.9:rc:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:0.9.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:0.9.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:0.9.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:0.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:0.10.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.0.6:*:linux:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.0.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.5:beta1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:seamonkey:1.0:*:alpha:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:seamonkey:1.0:beta:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:thunderbird:1.5:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-02T20:06Z",
    "lastModifiedDate" : "2018-10-19T15:43Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0295",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "mozilla",
            "product" : {
              "product_data" : [ {
                "product_name" : "firefox",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.5",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "seamonkey",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "thunderbird",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.5",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18700",
          "name" : "18700",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18704",
          "name" : "18704",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/22065",
          "name" : "22065",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1015570",
          "name" : "1015570",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/759273",
          "name" : "VU#759273",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.mozilla.org/security/announce/2006/mfsa2006-04.html",
          "name" : "http://www.mozilla.org/security/announce/2006/mfsa2006-04.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/446657/100/200/threaded",
          "name" : "SSRT061236",
          "refsource" : "HP",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16476",
          "name" : "16476",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA06-038A.html",
          "name" : "TA06-038A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0413",
          "name" : "ADV-2006-0413",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/3749",
          "name" : "ADV-2006-3749",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://bugzilla.mozilla.org/show_bug.cgi?id=319296",
          "name" : "https://bugzilla.mozilla.org/show_bug.cgi?id=319296",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24433",
          "name" : "mozilla-queryinterface-memory-corruption(24433)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1562",
          "name" : "oval:org.mitre.oval:def:1562",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Mozilla Firefox 1.5, Thunderbird 1.5 if Javascript is enabled in mail, and SeaMonkey before 1.0 might allow remote attackers to execute arbitrary code via the QueryInterface method of the built-in Location and Navigator objects, which leads to memory corruption."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:seamonkey:1.0:*:alpha:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:seamonkey:1.0:beta:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:thunderbird:1.5:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:H/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "HIGH",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.1
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 4.9,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2006-02-02T20:06Z",
    "lastModifiedDate" : "2018-10-19T15:43Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0296",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "mozilla",
            "product" : {
              "product_data" : [ {
                "product_name" : "firefox",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.9.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.9.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.9.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.10.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "seamonkey",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2006.26/SCOSA-2006.26.txt",
          "name" : "SCOSA-2006.26",
          "refsource" : "SCO",
          "tags" : [ ]
        }, {
          "url" : "ftp://patches.sgi.com/support/free/security/advisories/20060201-01-U",
          "name" : "20060201-01-U",
          "refsource" : "SGI",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18700",
          "name" : "18700",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18703",
          "name" : "18703",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18704",
          "name" : "18704",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18705",
          "name" : "18705",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18706",
          "name" : "18706",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18708",
          "name" : "18708",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18709",
          "name" : "18709",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/19230",
          "name" : "19230",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/19746",
          "name" : "19746",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/19759",
          "name" : "19759",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/19780",
          "name" : "19780",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/19821",
          "name" : "19821",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/19823",
          "name" : "19823",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/19852",
          "name" : "19852",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/19862",
          "name" : "19862",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/19863",
          "name" : "19863",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/19902",
          "name" : "19902",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/19941",
          "name" : "19941",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/19950",
          "name" : "19950",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/20051",
          "name" : "20051",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/21033",
          "name" : "21033",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/21622",
          "name" : "21622",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/22065",
          "name" : "22065",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1015570",
          "name" : "1015570",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://sunsolve.sun.com/search/document.do?assetkey=1-26-102550-1",
          "name" : "102550",
          "refsource" : "SUNALERT",
          "tags" : [ ]
        }, {
          "url" : "http://sunsolve.sun.com/search/document.do?assetkey=1-26-228526-1",
          "name" : "228526",
          "refsource" : "SUNALERT",
          "tags" : [ ]
        }, {
          "url" : "http://support.avaya.com/elmodocs2/security/ASA-2006-205.htm",
          "name" : "http://support.avaya.com/elmodocs2/security/ASA-2006-205.htm",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2006/dsa-1044",
          "name" : "DSA-1044",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2006/dsa-1046",
          "name" : "DSA-1046",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2006/dsa-1051",
          "name" : "DSA-1051",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.gentoo.org/security/en/glsa/glsa-200604-12.xml",
          "name" : "GLSA-200604-12",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://www.gentoo.org/security/en/glsa/glsa-200604-18.xml",
          "name" : "GLSA-200604-18",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://www.gentoo.org/security/en/glsa/glsa-200605-09.xml",
          "name" : "GLSA-200605-09",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/592425",
          "name" : "VU#592425",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDKSA-2006:036",
          "name" : "MDKSA-2006:036",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDKSA-2006:037",
          "name" : "MDKSA-2006:037",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDKSA-2006:078",
          "name" : "MDKSA-2006:078",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.mozilla.org/security/announce/2006/mfsa2006-05.html",
          "name" : "http://www.mozilla.org/security/announce/2006/mfsa2006-05.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.novell.com/linux/security/advisories/2006_04_25.html",
          "name" : "SUSE-SA:2006:022",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/archives/fedora-announce-list/2006-February/msg00005.html",
          "name" : "FEDORA-2006-075",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/archives/fedora-announce-list/2006-February/msg00006.html",
          "name" : "FEDORA-2006-076",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2006-0199.html",
          "name" : "RHSA-2006:0199",
          "refsource" : "REDHAT",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2006-0200.html",
          "name" : "RHSA-2006:0200",
          "refsource" : "REDHAT",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2006-0330.html",
          "name" : "RHSA-2006:0330",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/425975/100/0/threaded",
          "name" : "FLSA:180036-1",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/425978/100/0/threaded",
          "name" : "FLSA-2006:180036-2",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/438730/100/0/threaded",
          "name" : "HPSBUX02122",
          "refsource" : "HP",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/446657/100/200/threaded",
          "name" : "SSRT061236",
          "refsource" : "HP",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16476",
          "name" : "16476",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA06-038A.html",
          "name" : "TA06-038A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0413",
          "name" : "ADV-2006-0413",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/3391",
          "name" : "ADV-2006-3391",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/3749",
          "name" : "ADV-2006-3749",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://bugzilla.mozilla.org/show_bug.cgi?id=319847",
          "name" : "https://bugzilla.mozilla.org/show_bug.cgi?id=319847",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24434",
          "name" : "mozilla-xuldocument-command-execution(24434)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11803",
          "name" : "oval:org.mitre.oval:def:11803",
          "refsource" : "OVAL",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1493",
          "name" : "oval:org.mitre.oval:def:1493",
          "refsource" : "OVAL",
          "tags" : [ ]
        }, {
          "url" : "https://usn.ubuntu.com/271-1/",
          "name" : "USN-271-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "https://usn.ubuntu.com/275-1/",
          "name" : "USN-275-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "https://usn.ubuntu.com/276-1/",
          "name" : "USN-276-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The XULDocument.persist function in Mozilla, Firefox before 1.5.0.1, and SeaMonkey before 1.0 does not validate the attribute name, which allows remote attackers to execute arbitrary Javascript by injecting RDF data into the user's localstore.rdf file."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:0.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:0.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:0.9:rc:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:0.9.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:0.9.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:0.9.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:0.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:0.10.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.0.6:*:linux:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.0.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.5:beta1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:seamonkey:1.0:*:alpha:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:seamonkey:1.0:beta:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-02T20:06Z",
    "lastModifiedDate" : "2018-10-19T15:43Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0297",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "mozilla",
            "product" : {
              "product_data" : [ {
                "product_name" : "firefox",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.5",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "seamonkey",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "thunderbird",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.5",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18700",
          "name" : "18700",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18704",
          "name" : "18704",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/22065",
          "name" : "22065",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1015570",
          "name" : "1015570",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.mozilla.org/security/announce/2006/mfsa2006-06.html",
          "name" : "http://www.mozilla.org/security/announce/2006/mfsa2006-06.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/446657/100/200/threaded",
          "name" : "SSRT061236",
          "refsource" : "HP",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16476",
          "name" : "16476",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0413",
          "name" : "ADV-2006-0413",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/3749",
          "name" : "ADV-2006-3749",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://bugzilla.mozilla.org/show_bug.cgi?id=319872",
          "name" : "https://bugzilla.mozilla.org/show_bug.cgi?id=319872",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://bugzilla.mozilla.org/show_bug.cgi?id=322215",
          "name" : "https://bugzilla.mozilla.org/show_bug.cgi?id=322215",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24435",
          "name" : "mozilla-component-integer-overflow(24435)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1339",
          "name" : "oval:org.mitre.oval:def:1339",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple integer overflows in Mozilla Firefox 1.5, Thunderbird 1.5 if Javascript is enabled in mail, and SeaMonkey before 1.0 might allow remote attackers to execute arbitrary code via the (1) EscapeAttributeValue in jsxml.c for E4X, (2) nsSVGCairoSurface::Init in SVG, and (3) nsCanvasRenderingContext2D.cpp in Canvas."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.5:beta1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:seamonkey:1.0:*:alpha:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:seamonkey:1.0:beta:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:thunderbird:1.5:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:H/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "HIGH",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.1
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 4.9,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2006-02-02T22:02Z",
    "lastModifiedDate" : "2018-10-19T15:44Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0298",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "mozilla",
            "product" : {
              "product_data" : [ {
                "product_name" : "firefox",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.5",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "seamonkey",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-20"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18700",
          "name" : "18700",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18704",
          "name" : "18704",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/22065",
          "name" : "22065",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1015570",
          "name" : "1015570",
          "refsource" : "SECTRACK",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.mozilla.org/security/announce/2006/mfsa2006-07.html",
          "name" : "http://www.mozilla.org/security/announce/2006/mfsa2006-07.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/446657/100/200/threaded",
          "name" : "SSRT061236",
          "refsource" : "HP",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16476",
          "name" : "16476",
          "refsource" : "BID",
          "tags" : [ "Exploit", "Patch" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0413",
          "name" : "ADV-2006-0413",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/3749",
          "name" : "ADV-2006-3749",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24436",
          "name" : "mozilla-xml-parser-dos(24436)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A677",
          "name" : "oval:org.mitre.oval:def:677",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The XML parser in Mozilla Firefox before 1.5.0.1 and SeaMonkey before 1.0 allows remote attackers to cause a denial of service (crash) and possibly read sensitive data via unknown attack vectors that trigger an out-of-bounds read."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.5:beta1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:seamonkey:1.0:*:alpha:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:seamonkey:1.0:beta:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2006-02-02T22:02Z",
    "lastModifiedDate" : "2018-10-19T15:44Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0299",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "mozilla",
            "product" : {
              "product_data" : [ {
                "product_name" : "firefox",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.5",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "seamonkey",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "thunderbird",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.5",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18700",
          "name" : "18700",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18704",
          "name" : "18704",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/22065",
          "name" : "22065",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1015570",
          "name" : "1015570",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.mozilla.org/security/announce/2006/mfsa2006-08.html",
          "name" : "http://www.mozilla.org/security/announce/2006/mfsa2006-08.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/446657/100/200/threaded",
          "name" : "SSRT061236",
          "refsource" : "HP",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16476",
          "name" : "16476",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0413",
          "name" : "ADV-2006-0413",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/3749",
          "name" : "ADV-2006-3749",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://bugzilla.mozilla.org/show_bug.cgi?id=322312",
          "name" : "https://bugzilla.mozilla.org/show_bug.cgi?id=322312",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24437",
          "name" : "mozilla-e4x-security-bypass(24437)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1625",
          "name" : "oval:org.mitre.oval:def:1625",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The E4X implementation in Mozilla Firefox before 1.5.0.1, Thunderbird 1.5 if running Javascript in mail, and SeaMonkey before 1.0 exposes the internal \"AnyName\" object to external interfaces, which allows multiple cooperating domains to exchange information in violation of the same origin restrictions."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.5:beta1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:seamonkey:1.0:*:alpha:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:seamonkey:1.0:beta:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:thunderbird:1.5:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 6.4
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-02T23:06Z",
    "lastModifiedDate" : "2018-10-19T15:44Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0300",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "gnu",
            "product" : {
              "product_data" : [ {
                "product_name" : "tar",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.14.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.15.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.15.90",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://docs.info.apple.com/article.html?artnum=305214",
          "name" : "http://docs.info.apple.com/article.html?artnum=305214",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://docs.info.apple.com/article.html?artnum=305391",
          "name" : "http://docs.info.apple.com/article.html?artnum=305391",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://lists.apple.com/archives/Security-announce/2007/Apr/msg00001.html",
          "name" : "APPLE-SA-2007-04-19",
          "refsource" : "APPLE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.apple.com/archives/security-announce/2007/Mar/msg00002.html",
          "name" : "APPLE-SA-2007-03-13",
          "refsource" : "APPLE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.gnu.org/archive/html/bug-tar/2006-02/msg00051.html",
          "name" : "[Bug-tar] 20060220 tar 1.15.90 released",
          "refsource" : "MLIST",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18973",
          "name" : "18973",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18976",
          "name" : "18976",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18999",
          "name" : "18999",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/19016",
          "name" : "19016",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/19093",
          "name" : "19093",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/19130",
          "name" : "19130",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/19152",
          "name" : "19152",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/19236",
          "name" : "19236",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/20042",
          "name" : "20042",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24479",
          "name" : "24479",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/24966",
          "name" : "24966",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/480",
          "name" : "480",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/543",
          "name" : "543",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1015705",
          "name" : "1015705",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://sunsolve.sun.com/search/document.do?assetkey=1-26-241646-1",
          "name" : "241646",
          "refsource" : "SUNALERT",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2006/dsa-987",
          "name" : "DSA-987",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.gentoo.org/security/en/glsa/glsa-200603-06.xml",
          "name" : "GLSA-200603-06",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://www.novell.com/linux/security/advisories/2006_05_sr.html",
          "name" : "SUSE-SR:2006:005",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://www.openpkg.org/security/OpenPKG-SA-2006.006-tar.html",
          "name" : "OpenPKG-SA-2006.006",
          "refsource" : "OPENPKG",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/23371",
          "name" : "23371",
          "refsource" : "OSVDB",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2006-0232.html",
          "name" : "RHSA-2006:0232",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/430299/100/0/threaded",
          "name" : "FLSA:183571-2",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16764",
          "name" : "16764",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.trustix.org/errata/2006/0010",
          "name" : "2006-0010",
          "refsource" : "TRUSTIX",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA07-072A.html",
          "name" : "TA07-072A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA07-109A.html",
          "name" : "TA07-109A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0684",
          "name" : "ADV-2006-0684",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0930",
          "name" : "ADV-2007-0930",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/1470",
          "name" : "ADV-2007-1470",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/2518",
          "name" : "ADV-2008-2518",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://wwwnew.mandriva.com/security/advisories?name=MDKSA-2006:046",
          "name" : "MDKSA-2006:046",
          "refsource" : "MANDRIVA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24855",
          "name" : "gnu-tar-pax-headers-bo(24855)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5252",
          "name" : "oval:org.mitre.oval:def:5252",
          "refsource" : "OVAL",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5978",
          "name" : "oval:org.mitre.oval:def:5978",
          "refsource" : "OVAL",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5993",
          "name" : "oval:org.mitre.oval:def:5993",
          "refsource" : "OVAL",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6094",
          "name" : "oval:org.mitre.oval:def:6094",
          "refsource" : "OVAL",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9295",
          "name" : "oval:org.mitre.oval:def:9295",
          "refsource" : "OVAL",
          "tags" : [ ]
        }, {
          "url" : "https://usn.ubuntu.com/257-1/",
          "name" : "USN-257-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Buffer overflow in tar 1.14 through 1.15.90 allows user-assisted attackers to cause a denial of service (application crash) and possibly execute code via unspecified vectors involving PAX extended headers."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:gnu:tar:1.14:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:gnu:tar:1.14.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:gnu:tar:1.15:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:gnu:tar:1.15.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:gnu:tar:1.15.90:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:H/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "HIGH",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.1
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 4.9,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2006-02-24T00:02Z",
    "lastModifiedDate" : "2018-10-19T15:44Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0301",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "xpdf",
            "product" : {
              "product_data" : [ {
                "product_name" : "xpdf",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2006.15/SCOSA-2006.15.txt",
          "name" : "SCOSA-2006.15",
          "refsource" : "SCO",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2006-0206.html",
          "name" : "RHSA-2006:0206",
          "refsource" : "REDHAT",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18274",
          "name" : "18274",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18677",
          "name" : "18677",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18707",
          "name" : "18707",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18825",
          "name" : "18825",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18826",
          "name" : "18826",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18834",
          "name" : "18834",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18837",
          "name" : "18837",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18838",
          "name" : "18838",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18839",
          "name" : "18839",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18860",
          "name" : "18860",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18862",
          "name" : "18862",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18864",
          "name" : "18864",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18875",
          "name" : "18875",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18882",
          "name" : "18882",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18908",
          "name" : "18908",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18913",
          "name" : "18913",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18983",
          "name" : "18983",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/19377",
          "name" : "19377",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/470",
          "name" : "470",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1015576",
          "name" : "1015576",
          "refsource" : "SECTRACK",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://slackware.com/security/viewer.php?l=slackware-security&y=2006&m=slackware-security.472683",
          "name" : "SSA:2006-045-09",
          "refsource" : "SLACKWARE",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://slackware.com/security/viewer.php?l=slackware-security&y=2006&m=slackware-security.474747",
          "name" : "SSA:2006-045-04",
          "refsource" : "SLACKWARE",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.debian.org/security/2006/dsa-971",
          "name" : "DSA-971",
          "refsource" : "DEBIAN",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.debian.org/security/2006/dsa-972",
          "name" : "DSA-972",
          "refsource" : "DEBIAN",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.debian.org/security/2006/dsa-974",
          "name" : "DSA-974",
          "refsource" : "DEBIAN",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.gentoo.org/security/en/glsa/glsa-200602-04.xml",
          "name" : "GLSA-200602-04",
          "refsource" : "GENTOO",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.gentoo.org/security/en/glsa/glsa-200602-05.xml",
          "name" : "GLSA-200602-05",
          "refsource" : "GENTOO",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.gentoo.org/security/en/glsa/glsa-200602-12.xml",
          "name" : "GLSA-200602-12",
          "refsource" : "GENTOO",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.kde.org/info/security/advisory-20060202-1.txt",
          "name" : "http://www.kde.org/info/security/advisory-20060202-1.txt",
          "refsource" : "MISC",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDKSA-2006:030",
          "name" : "MDKSA-2006:030",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDKSA-2006:031",
          "name" : "MDKSA-2006:031",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDKSA-2006:032",
          "name" : "MDKSA-2006:032",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/archives/fedora-announce-list/2006-February/msg00039.html",
          "name" : "FEDORA-2006-103",
          "refsource" : "FEDORA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2006-0201.html",
          "name" : "RHSA-2006:0201",
          "refsource" : "REDHAT",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/423899/100/0/threaded",
          "name" : "20060202 [KDE Security Advisory] kpdf/xpdf heap based buffer overflow",
          "refsource" : "BUGTRAQ",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/427990/100/0/threaded",
          "name" : "FLSA:175404",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/usn-249-1",
          "name" : "USN-249-1",
          "refsource" : "UBUNTU",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0389",
          "name" : "ADV-2006-0389",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0422",
          "name" : "ADV-2006-0422",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://bugzilla.novell.com/show_bug.cgi?id=141242",
          "name" : "https://bugzilla.novell.com/show_bug.cgi?id=141242",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=179046",
          "name" : "https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=179046",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24391",
          "name" : "xpdf-splash-bo(24391)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10850",
          "name" : "oval:org.mitre.oval:def:10850",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Heap-based buffer overflow in Splash.cc in xpdf, as used in other products such as (1) poppler, (2) kdegraphics, (3) gpdf, (4) pdfkit.framework, and others, allows attackers to cause a denial of service and possibly execute arbitrary code via crafted splash images that produce certain values that exceed the width or height of the associated bitmap."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:xpdf:xpdf:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-30T22:03Z",
    "lastModifiedDate" : "2018-10-19T15:44Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0302",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "zyxel",
            "product" : {
              "product_data" : [ {
                "product_name" : "p2000w_version_2_voip_wifi_phone",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "wv.00.02",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.grok.org.uk/pipermail/full-disclosure/2006-January/041438.html",
          "name" : "20060116 ZyXel P2000W (Version 2) VoIP wireless phone undocumented port UDP/9090",
          "refsource" : "FULLDISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18511",
          "name" : "18511",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/22516",
          "name" : "22516",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16285",
          "name" : "16285",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24145",
          "name" : "zyxel-p2000w-default-port(24145)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "ZyXel P2000W VoIP 802.11b Wireless Phone running firmware WV.00.02 allows remote attackers to obtain sensitive information, such as MAC address and software version, by directly accessing UDP port 9090."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:zyxel:p2000w_version_2_voip_wifi_phone:wv.00.02:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-19T00:03Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0303",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "joomla",
            "product" : {
              "product_data" : [ {
                "product_name" : "joomla",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.5",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18513",
          "name" : "18513",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.joomla.org/content/view/738/66/",
          "name" : "http://www.joomla.org/content/view/738/66/",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple unspecified vulnerabilities in the (1) publishing component, (2) Contact Component, (3) TinyMCE Compressor, and (4) other components in Joomla! 1.0.5 and earlier have unknown impact and attack vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:joomla:joomla:1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:joomla:joomla:1.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:joomla:joomla:1.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:joomla:joomla:1.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:joomla:joomla:1.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:joomla:joomla:1.0.5:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-19T00:03Z",
    "lastModifiedDate" : "2008-09-05T20:58Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0304",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "achal_dhir",
            "product" : {
              "product_data" : [ {
                "product_name" : "dual_dhcp_dns_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://aluigi.altervista.org/adv/dualsbof-adv.txt",
          "name" : "http://aluigi.altervista.org/adv/dualsbof-adv.txt",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18486",
          "name" : "18486",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1015495",
          "name" : "1015495",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16298",
          "name" : "16298",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0245",
          "name" : "ADV-2006-0245",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24191",
          "name" : "dualdhcpdns-options-field-bo(24191)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Buffer overflow in Dual DHCP DNS Server 1.0 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via the DHCP options field."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:achal_dhir:dual_dhcp_dns_server:1.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-19T00:03Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0305",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "clipcomm",
            "product" : {
              "product_data" : [ {
                "product_name" : "cp-100e_voip_wifi_phone",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.1.60",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "cpw-100e_voip_wifi_phone",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.1.12",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.grok.org.uk/pipermail/full-disclosure/2006-January/041436.html",
          "name" : "20060116 Clipcomm CPW-100E VoIP wireless handset phone open debug service TCP/60023",
          "refsource" : "FULLDISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://lists.grok.org.uk/pipermail/full-disclosure/2006-January/041439.html",
          "name" : "20060116 Clipcomm CP-100E VoIP wireless desktop phone open debug service TCP/60023",
          "refsource" : "FULLDISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18505",
          "name" : "18505",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16289",
          "name" : "16289",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24144",
          "name" : "clipcomm-cp100e-default-port(24144)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Clipcomm CPW-100E VoIP 802.11b Wireless Handset Phone running firmware 1.1.12 (051129) and CP-100E VoIP 802.11b Wireless Phone running firmware 1.1.60 allows remote attackers to gain unauthorized access via the debug service on TCP port 60023."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:clipcomm:cp-100e_voip_wifi_phone:1.1.60:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:clipcomm:cpw-100e_voip_wifi_phone:1.1.12:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-19T00:03Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0306",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ca",
            "product" : {
              "product_data" : [ {
                "product_name" : "brightstor_arcserve_backup_laptops_desktops",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "11.1",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "brightstor_mobile_backup",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "r4.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "business_protection_suite",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "desktop_protection_suite",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "server_protection_suite",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "unicenter_remote_control",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0_build_6.0.56.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0_build_6.0.74",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-399"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18531",
          "name" : "18531",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1015504",
          "name" : "1015504",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://supportconnectw.ca.com/public/ca_common_docs/dmdeploysecurity_notice.asp",
          "name" : "http://supportconnectw.ca.com/public/ca_common_docs/dmdeploysecurity_notice.asp",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.designfolks.com.au/karma/DMPrimer/",
          "name" : "http://www.designfolks.com.au/karma/DMPrimer/",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/22529",
          "name" : "22529",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/422381/100/0/threaded",
          "name" : "20060118 CAID 33756 - DM Deployment Common Component Vulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16276",
          "name" : "16276",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0236",
          "name" : "ADV-2006-0236",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www3.ca.com/securityadvisor/vulninfo/vuln.aspx?id=33756",
          "name" : "http://www3.ca.com/securityadvisor/vulninfo/vuln.aspx?id=33756",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The DM Primer (dmprimer.exe) in the DM Deployment Common Component in Computer Associates (CA) BrightStor Mobile Backup r4.0, BrightStor ARCserve Backup for Laptops & Desktops r11.0, r11.1, r11.1 SP1, Unicenter Remote Control 6.0, 6.0 SP1, CA Desktop Protection Suite r2, CA Server Protection Suite r2, and CA Business Protection Suite r2 allows remote attackers to cause a denial of service (CPU consumption or application hang) via a large network packet, which causes a WSAEMESGSIZE error code that is not handled, leading to a thread exit."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:brightstor_arcserve_backup_laptops_desktops:11.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:brightstor_arcserve_backup_laptops_desktops:11.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:brightstor_arcserve_backup_laptops_desktops:11.1:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:brightstor_mobile_backup:r4.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:business_protection_suite:2.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:desktop_protection_suite:2.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:server_protection_suite:2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:unicenter_remote_control:5.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:unicenter_remote_control:6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:unicenter_remote_control:6.0:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:unicenter_remote_control:6.0:sp1:*:en:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:unicenter_remote_control:6.0:sp1:*:fr:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:unicenter_remote_control:6.0_build_6.0.56.3:*:*:en:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:unicenter_remote_control:6.0_build_6.0.74:*:*:de:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:unicenter_remote_control:6.0_build_6.0.74:*:*:en:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:unicenter_remote_control:6.0_build_6.0.74:*:*:fr:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-19T00:03Z",
    "lastModifiedDate" : "2018-10-19T15:44Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0307",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ca",
            "product" : {
              "product_data" : [ {
                "product_name" : "brightstor_arcserve_backup_laptops_desktops",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "11.1",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "brightstor_mobile_backup",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "r4.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "business_protection_suite",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "desktop_protection_suite",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "server_protection_suite",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "unicenter_remote_control",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0_build_6.0.56.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0_build_6.0.74",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-399"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18531",
          "name" : "18531",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1015504",
          "name" : "1015504",
          "refsource" : "SECTRACK",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://supportconnectw.ca.com/public/ca_common_docs/dmdeploysecurity_notice.asp",
          "name" : "http://supportconnectw.ca.com/public/ca_common_docs/dmdeploysecurity_notice.asp",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/22529",
          "name" : "22529",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/422381/100/0/threaded",
          "name" : "20060118 CAID 33756 - DM Deployment Common Component Vulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16276",
          "name" : "16276",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0236",
          "name" : "ADV-2006-0236",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www3.ca.com/securityadvisor/vulninfo/vuln.aspx?id=33756",
          "name" : "http://www3.ca.com/securityadvisor/vulninfo/vuln.aspx?id=33756",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The DM Primer in the DM Deployment Common Component in Computer Associates (CA) BrightStor Mobile Backup r4.0, BrightStor ARCserve Backup for Laptops & Desktops r11.0, r11.1, r11.1 SP1, Unicenter Remote Control 6.0, 6.0 SP1, CA Desktop Protection Suite r2, CA Server Protection Suite r2, and CA Business Protection Suite r2 allows remote attackers to cause a denial of service (CPU consumption and log file consumption) via unspecified \"unrecognized network messages\" that are not properly handled."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:brightstor_arcserve_backup_laptops_desktops:11.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:brightstor_arcserve_backup_laptops_desktops:11.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:brightstor_arcserve_backup_laptops_desktops:11.1:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:brightstor_mobile_backup:r4.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:business_protection_suite:2.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:desktop_protection_suite:2.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:server_protection_suite:2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:unicenter_remote_control:5.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:unicenter_remote_control:6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:unicenter_remote_control:6.0:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:unicenter_remote_control:6.0:sp1:*:en:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:unicenter_remote_control:6.0:sp1:*:fr:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:unicenter_remote_control:6.0_build_6.0.56.3:*:*:en:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:unicenter_remote_control:6.0_build_6.0.74:*:*:de:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:unicenter_remote_control:6.0_build_6.0.74:*:*:en:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:unicenter_remote_control:6.0_build_6.0.74:*:*:fr:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-19T00:03Z",
    "lastModifiedDate" : "2018-10-19T15:44Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0308",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "htmltonuke",
            "product" : {
              "product_data" : [ {
                "product_name" : "htmltonuke",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0_alpha",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-94"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/16282",
          "name" : "16282",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/33092",
          "name" : "htmltonuke-htmltonuke-file-include(33092)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/3524",
          "name" : "3524",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "PHP remote file inclusion vulnerability in htmltonuke.php in the htmltonuke 2.0 alpha, and possibly other versions, module for PHP-Nuke allows remote attackers to execute arbitrary PHP code via a URL in the filnavn parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:htmltonuke:htmltonuke:2.0_alpha:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-19T00:03Z",
    "lastModifiedDate" : "2017-10-11T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0309",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "linksys",
            "product" : {
              "product_data" : [ {
                "product_name" : "befvp41",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.01.04",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18461",
          "name" : "18461",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1015490",
          "name" : "1015490",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/421929/100/0/threaded",
          "name" : "20060113 Linksys VPN Router (BEFVP41) DoS Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/422064/100/0/threaded",
          "name" : "20060116 Re: Linksys VPN Router (BEFVP41) DoS Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/422266/100/0/threaded",
          "name" : "20060117 Re: Linksys VPN Router (BEFVP41) DoS Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16307",
          "name" : "16307",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0238",
          "name" : "ADV-2006-0238",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24125",
          "name" : "linksys-null-length-dos(24125)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Linksys BEFVP41 VPN Router 2.0 with firmware 1.01.04 allows remote attackers on the local network, to cause a denial of service via IP packets with a null IP option length."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:linksys:befvp41:1.01.04:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 4.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-19T01:03Z",
    "lastModifiedDate" : "2018-10-19T15:44Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0310",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "mike_helton",
            "product" : {
              "product_data" : [ {
                "product_name" : "aoblogger",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://archives.neohapsis.com/archives/bugtraq/2006-01/0322.html",
          "name" : "20060117 [eVuln] aoblogger Multiple Vulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://evuln.com/vulns/37/summary.html",
          "name" : "http://evuln.com/vulns/37/summary.html",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://mikeheltonisawesome.com/viewcomments.php?idd=46",
          "name" : "http://mikeheltonisawesome.com/viewcomments.php?idd=46",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/16889",
          "name" : "16889",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/22526",
          "name" : "22526",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16286",
          "name" : "16286",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0240",
          "name" : "ADV-2006-0240",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24141",
          "name" : "aoblogger-url-xss(24141)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in aoblogger 2.3 allows remote attackers to inject arbitrary Javascript via a javascript URI in the BBcode url tag."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mike_helton:aoblogger:2.3:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-19T01:03Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0311",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "mike_helton",
            "product" : {
              "product_data" : [ {
                "product_name" : "aoblogger",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://archives.neohapsis.com/archives/bugtraq/2006-01/0322.html",
          "name" : "20060117 [eVuln] aoblogger Multiple Vulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://evuln.com/vulns/37/summary.html",
          "name" : "http://evuln.com/vulns/37/summary.html",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://mikeheltonisawesome.com/viewcomments.php?idd=46",
          "name" : "http://mikeheltonisawesome.com/viewcomments.php?idd=46",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/16889",
          "name" : "16889",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/22527",
          "name" : "22527",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16286",
          "name" : "16286",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0240",
          "name" : "ADV-2006-0240",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24142",
          "name" : "aoblogger-login-sql-injection(24142)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in login.php in aoblogger 2.3 allows remote attackers to execute arbitrary SQL commands via the username parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mike_helton:aoblogger:2.3:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-19T01:03Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0312",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "mike_helton",
            "product" : {
              "product_data" : [ {
                "product_name" : "aoblogger",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://archives.neohapsis.com/archives/bugtraq/2006-01/0322.html",
          "name" : "20060117 [eVuln] aoblogger Multiple Vulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://evuln.com/vulns/37/summary.html",
          "name" : "http://evuln.com/vulns/37/summary.html",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://mikeheltonisawesome.com/viewcomments.php?idd=46",
          "name" : "http://mikeheltonisawesome.com/viewcomments.php?idd=46",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/16889",
          "name" : "16889",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16286",
          "name" : "16286",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0240",
          "name" : "ADV-2006-0240",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24143",
          "name" : "aoblogger-create-security-bypass(24143)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "create.php in aoblogger 2.3 allows remote attackers to bypass authentication and create new blog entries by setting the uza parameter to 1."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mike_helton:aoblogger:2.3:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-19T01:03Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0313",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "pdfdirectory",
            "product" : {
              "product_data" : [ {
                "product_name" : "pdfdirectory",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.2.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.2.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.2.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.2.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.2.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.2.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.2.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.2.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.2.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.2.11",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18459",
          "name" : "18459",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://sourceforge.net/project/shownotes.php?release_id=382411&group_id=122682",
          "name" : "http://sourceforge.net/project/shownotes.php?release_id=382411&group_id=122682",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.osvdb.org/22403",
          "name" : "22403",
          "refsource" : "OSVDB",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.osvdb.org/22404",
          "name" : "22404",
          "refsource" : "OSVDB",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.osvdb.org/22405",
          "name" : "22405",
          "refsource" : "OSVDB",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.osvdb.org/22406",
          "name" : "22406",
          "refsource" : "OSVDB",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.osvdb.org/22407",
          "name" : "22407",
          "refsource" : "OSVDB",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.osvdb.org/22408",
          "name" : "22408",
          "refsource" : "OSVDB",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.osvdb.org/22409",
          "name" : "22409",
          "refsource" : "OSVDB",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.osvdb.org/22410",
          "name" : "22410",
          "refsource" : "OSVDB",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.osvdb.org/22411",
          "name" : "22411",
          "refsource" : "OSVDB",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.osvdb.org/22412",
          "name" : "22412",
          "refsource" : "OSVDB",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.osvdb.org/22413",
          "name" : "22413",
          "refsource" : "OSVDB",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.osvdb.org/22414",
          "name" : "22414",
          "refsource" : "OSVDB",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.osvdb.org/22415",
          "name" : "22415",
          "refsource" : "OSVDB",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16273",
          "name" : "16273",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0231",
          "name" : "ADV-2006-0231",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple SQL injection vulnerabilities in PDFdirectory before 1.0 allow remote attackers to execute arbitrary SQL commands via multiple unspecified vectors involving (1) util.php, (2) userpref.php, (3) user.php, (4) uploadfrm.php, (5) title.php, (6) team.php, (7) stats.php, (8) page.php, (9) org.php, (10) member.php, (11) index.php, (12) group.php, or (13) anniv.php."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pdfdirectory:pdfdirectory:0.2.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pdfdirectory:pdfdirectory:0.2.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pdfdirectory:pdfdirectory:0.2.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pdfdirectory:pdfdirectory:0.2.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pdfdirectory:pdfdirectory:0.2.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pdfdirectory:pdfdirectory:0.2.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pdfdirectory:pdfdirectory:0.2.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pdfdirectory:pdfdirectory:0.2.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pdfdirectory:pdfdirectory:0.2.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pdfdirectory:pdfdirectory:0.2.11:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-19T01:03Z",
    "lastModifiedDate" : "2011-03-08T02:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0314",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "pdfdirectory",
            "product" : {
              "product_data" : [ {
                "product_name" : "pdfdirectory",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.2.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.2.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.2.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.2.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.2.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.2.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.2.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.2.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.2.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.2.11",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://sourceforge.net/project/shownotes.php?release_id=382411&group_id=122682",
          "name" : "http://sourceforge.net/project/shownotes.php?release_id=382411&group_id=122682",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/22402",
          "name" : "22402",
          "refsource" : "OSVDB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "PDFdirectory before 1.0 stores sensitive data in plaintext, which allows remote attackers to obtain arbitrary users' passwords by direct queries to the database, possibly via one of the SQL injection vulnerabilities."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pdfdirectory:pdfdirectory:0.2.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pdfdirectory:pdfdirectory:0.2.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pdfdirectory:pdfdirectory:0.2.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pdfdirectory:pdfdirectory:0.2.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pdfdirectory:pdfdirectory:0.2.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pdfdirectory:pdfdirectory:0.2.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pdfdirectory:pdfdirectory:0.2.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pdfdirectory:pdfdirectory:0.2.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pdfdirectory:pdfdirectory:0.2.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pdfdirectory:pdfdirectory:0.2.11:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-19T01:03Z",
    "lastModifiedDate" : "2011-03-08T02:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0315",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "indexcor",
            "product" : {
              "product_data" : [ {
                "product_name" : "ezdatabase",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.1.1",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://archives.neohapsis.com/archives/fulldisclosure/2006-01/0515.html",
          "name" : "20060115 EZDatabase Directory Transversal, XSS and Path Disclosure Vulnerability",
          "refsource" : "FULLDISC",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18043",
          "name" : "18043",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/22684",
          "name" : "22684",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/422071/100/0/threaded",
          "name" : "20060115 EZDatabase Directory Transversal, XSS and Path Disclosure Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16257",
          "name" : "16257",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://zur.homelinux.com/Advisories/ezdatabase_dir_trans.txt",
          "name" : "http://zur.homelinux.com/Advisories/ezdatabase_dir_trans.txt",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24134",
          "name" : "ezdatabase-index-p-xss(24134)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24135",
          "name" : "ezdatabase-index-p-path-disclosure(24135)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "index.php in EZDatabase before 2.1.2 does not properly cleanse the p parameter before constructing and including a .php filename, which allows remote attackers to conduct directory traversal attacks, and produces resultant cross-site scripting (XSS) and path disclosure."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:indexcor:ezdatabase:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "2.1.1"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-19T01:03Z",
    "lastModifiedDate" : "2018-10-19T15:44Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0316",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "aol",
            "product" : {
              "product_data" : [ {
                "product_name" : "aol_client_software",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://news.com.com/2061-10789_3-6027865.html?part=rss&tag=6027865&subj=news",
          "name" : "http://news.com.com/2061-10789_3-6027865.html?part=rss&tag=6027865&subj=news",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18521",
          "name" : "18521",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1015494",
          "name" : "1015494",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/715730",
          "name" : "VU#715730",
          "refsource" : "CERT-VN",
          "tags" : [ "Patch", "Third Party Advisory", "US Government Resource" ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/MIMG-6KRSQP",
          "name" : "http://www.kb.cert.org/vuls/id/MIMG-6KRSQP",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/22486",
          "name" : "22486",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16262",
          "name" : "16262",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0221",
          "name" : "ADV-2006-0221",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24160",
          "name" : "aol-youvegotpictures-activex-bo(24160)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Buffer overflow in YGPPicFinder.DLL in AOL You've Got Pictures (YGP) Picture Finder Tool ActiveX Control, as used in AOL 8.0, 8.0 Plus, and 9.0 Classic, allows remote attackers to execute arbitrary code via unspecified vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:aol:aol_client_software:8.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:aol:aol_client_software:8.0:*:plus:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:aol:aol_client_software:9.0:*:classic:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2006-01-19T01:03Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0317",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "redkernel",
            "product" : {
              "product_data" : [ {
                "product_name" : "referrer_tracker",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.1.0_3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18473",
          "name" : "18473",
          "refsource" : "SECUNIA",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16266",
          "name" : "16266",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0197",
          "name" : "ADV-2006-0197",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24151",
          "name" : "referertracker-rkrtstats-xss(24151)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in rkrt_stats.php in RedKernel Referrer Tracker 1.1.0-3 allows remote attackers to inject arbitrary web script or HTML via a query string value as a GET, which is stored in the $QUERY_STRING variable.  NOTE: the provenance of this information is unknown; portions of the details are obtained from third party information."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:redkernel:referrer_tracker:1.1.0_3:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-19T01:03Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0318",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "insane_visions",
            "product" : {
              "product_data" : [ {
                "product_name" : "blogphp",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://evuln.com/vulns/34/summary",
          "name" : "http://evuln.com/vulns/34/summary",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18467",
          "name" : "18467",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/22495",
          "name" : "22495",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/422137/100/0/threaded",
          "name" : "20060117 [eVuln] BlogPHP Authentication Bypass",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16269",
          "name" : "16269",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0204",
          "name" : "ADV-2006-0204",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24131",
          "name" : "blogphp-index-bypass-security(24131)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in index.php in BlogPHP 1.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands and bypass authentication via the username parameter in a login action."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:insane_visions:blogphp:1.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-19T01:03Z",
    "lastModifiedDate" : "2018-10-19T15:44Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0319",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "farmers_wife",
            "product" : {
              "product_data" : [ {
                "product_name" : "farmers_wife",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.4_sp1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://marc.info/?l=full-disclosure&m=113717162320654&w=2",
          "name" : "20060113 Farmers wife 4.4 sp1 remote SYSTEM access",
          "refsource" : "FULLDISC",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18508",
          "name" : "18508",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.lort.dk/DSR-farmerswife44sp1.pl",
          "name" : "http://www.lort.dk/DSR-farmerswife44sp1.pl",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.osvdb.org/22496",
          "name" : "22496",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16321",
          "name" : "16321",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24190",
          "name" : "farmerswife-ftp-directory-traversal(24190)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Directory traversal vulnerability in the FTP server (port 22003/tcp) in Farmers WIFE 4.4 SP1 allows remote attackers to create arbitrary files via \"..\" (dot dot) sequences in a (1) PUT, (2) SIZE, and possibly other commands."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:farmers_wife:farmers_wife:4.4_sp1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-19T01:03Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0320",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "bit_5_blog",
            "product" : {
              "product_data" : [ {
                "product_name" : "bit_5_blog",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.01",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://evuln.com/vulns/31/summary",
          "name" : "http://evuln.com/vulns/31/summary",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18464",
          "name" : "18464",
          "refsource" : "SECUNIA",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/22445",
          "name" : "22445",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/422068/100/0/threaded",
          "name" : "20060115 [eVuln] Bit 5 Blog SQL Injection & Authentication Bypass Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16244",
          "name" : "16244",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0195",
          "name" : "ADV-2006-0195",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24124",
          "name" : "bit5blog-processlogin-sql-injection(24124)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in admin/processlogin.php in Bit 5 Blog 8.01 allows remote attackers to execute arbitrary SQL commands and bypass authentication via the (1) username and (2) password parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bit_5_blog:bit_5_blog:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "8.01"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-19T01:03Z",
    "lastModifiedDate" : "2018-10-19T15:44Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0321",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "fetchmail",
            "product" : {
              "product_data" : [ {
                "product_name" : "fetchmail",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.3.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.3.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-20"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=348747",
          "name" : "http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=348747",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://developer.berlios.de/project/shownotes.php?release_id=8784",
          "name" : "http://developer.berlios.de/project/shownotes.php?release_id=8784",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://fetchmail.berlios.de/fetchmail-SA-2006-01.txt",
          "name" : "http://fetchmail.berlios.de/fetchmail-SA-2006-01.txt",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://lists.apple.com/archives/security-announce/2006//Aug/msg00000.html",
          "name" : "APPLE-SA-2006-08-01",
          "refsource" : "APPLE",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18571",
          "name" : "18571",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18895",
          "name" : "18895",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/21253",
          "name" : "21253",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1015527",
          "name" : "1015527",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://slackware.com/security/viewer.php?l=slackware-security&y=2006&m=slackware-security.443499",
          "name" : "SSA:2006-045-01",
          "refsource" : "SLACKWARE",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/22691",
          "name" : "22691",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/422936/100/0/threaded",
          "name" : "20060122 fetchmail security announcement fetchmail-SA-2006-01 (CVE-2006-0321)",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16365",
          "name" : "16365",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/19289",
          "name" : "19289",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA06-214A.html",
          "name" : "TA06-214A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0300",
          "name" : "ADV-2006-0300",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/3101",
          "name" : "ADV-2006-3101",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24265",
          "name" : "fetchmail-message-bounce-dos(24265)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "fetchmail 6.3.0 and other versions before 6.3.2 allows remote attackers to cause a denial of service (crash) via crafted e-mail messages that cause a free of an invalid pointer when fetchmail bounces the message to the originator or local postmaster."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:fetchmail:fetchmail:6.3.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:fetchmail:fetchmail:6.3.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-24T00:03Z",
    "lastModifiedDate" : "2018-10-19T15:44Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0322",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "mediawiki",
            "product" : {
              "product_data" : [ {
                "product_name" : "mediawiki",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.4.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4_beta1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4_beta2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4_beta3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4_beta4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4_beta5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4_beta6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5_alpha1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5_alpha2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5_beta1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5_beta2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5_beta3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5_beta4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5_rc2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5_rc3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5_rc4",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.suse.com/archive/suse-security-announce/2006-Feb/0001.html",
          "name" : "SUSE-SR:2006:003",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18711",
          "name" : "18711",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18717",
          "name" : "18717",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://sourceforge.net/project/shownotes.php?release_id=386609",
          "name" : "http://sourceforge.net/project/shownotes.php?release_id=386609",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0392",
          "name" : "ADV-2006-0392",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24478",
          "name" : "mediawiki-comment-format-dos(24478)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability the edit comment formatting functionality in MediaWiki 1.5.x before 1.5.6 and 1.4.x before 1.4.14 allows attackers to cause a denial of service (infinite loop) via \"certain malformed links.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mediawiki:mediawiki:1.4.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mediawiki:mediawiki:1.4.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mediawiki:mediawiki:1.4.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mediawiki:mediawiki:1.4.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mediawiki:mediawiki:1.4.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mediawiki:mediawiki:1.4.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mediawiki:mediawiki:1.4.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mediawiki:mediawiki:1.4.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mediawiki:mediawiki:1.4.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mediawiki:mediawiki:1.4.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mediawiki:mediawiki:1.4.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mediawiki:mediawiki:1.4.12:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mediawiki:mediawiki:1.4.13:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mediawiki:mediawiki:1.4.14:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mediawiki:mediawiki:1.4_beta1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mediawiki:mediawiki:1.4_beta2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mediawiki:mediawiki:1.4_beta3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mediawiki:mediawiki:1.4_beta4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mediawiki:mediawiki:1.4_beta5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mediawiki:mediawiki:1.4_beta6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mediawiki:mediawiki:1.5.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mediawiki:mediawiki:1.5.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mediawiki:mediawiki:1.5.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mediawiki:mediawiki:1.5.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mediawiki:mediawiki:1.5.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mediawiki:mediawiki:1.5.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mediawiki:mediawiki:1.5_alpha1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mediawiki:mediawiki:1.5_alpha2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mediawiki:mediawiki:1.5_beta1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mediawiki:mediawiki:1.5_beta2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mediawiki:mediawiki:1.5_beta3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mediawiki:mediawiki:1.5_beta4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mediawiki:mediawiki:1.5_rc2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mediawiki:mediawiki:1.5_rc3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mediawiki:mediawiki:1.5_rc4:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-19T21:03Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0323",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "realnetworks",
            "product" : {
              "product_data" : [ {
                "product_name" : "helix_player",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "realone_player",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "realplayer",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.5",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "rhapsody",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/19358",
          "name" : "19358",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/19362",
          "name" : "19362",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/19365",
          "name" : "19365",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/19390",
          "name" : "19390",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/690",
          "name" : "690",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1015806",
          "name" : "1015806",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.gentoo.org/security/en/glsa/glsa-200603-24.xml",
          "name" : "GLSA-200603-24",
          "refsource" : "GENTOO",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/231028",
          "name" : "VU#231028",
          "refsource" : "CERT-VN",
          "tags" : [ "Patch", "Third Party Advisory", "US Government Resource" ]
        }, {
          "url" : "http://www.novell.com/linux/security/advisories/2006_18_realplayer.html",
          "name" : "SUSE-SA:2006:018",
          "refsource" : "SUSE",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2006-0257.html",
          "name" : "RHSA-2006:0257",
          "refsource" : "REDHAT",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/430621/100/0/threaded",
          "name" : "20060411 Realplayer .SWF Multiple Remote Memory Corruption Vulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/17202",
          "name" : "17202",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.service.real.com/realplayer/security/03162006_player/en/",
          "name" : "http://www.service.real.com/realplayer/security/03162006_player/en/",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/1057",
          "name" : "ADV-2006-1057",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/25408",
          "name" : "realnetworks-swf-bo(25408)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Buffer overflow in swfformat.dll in multiple RealNetworks products and versions including RealPlayer 10.x, RealOne Player, Rhapsody 3, and Helix Player allows remote attackers to execute arbitrary code via a crafted SWF (Flash) file with (1) a size value that is less than the actual size, or (2) other unspecified manipulations."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:realnetworks:helix_player:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:realnetworks:realone_player:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:realnetworks:realplayer:10.0:gold:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:realnetworks:realplayer:10.0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:realnetworks:realplayer:10.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:realnetworks:rhapsody:3:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-03-23T23:06Z",
    "lastModifiedDate" : "2018-10-19T15:44Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0324",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "webspot",
            "product" : {
              "product_data" : [ {
                "product_name" : "webspotblogging",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://evuln.com/vulns/41/summary.html",
          "name" : "http://evuln.com/vulns/41/summary.html",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18560",
          "name" : "18560",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/356",
          "name" : "356",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1015522",
          "name" : "1015522",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/22670",
          "name" : "22670",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/422364/100/0/threaded",
          "name" : "20060119 [eVuln] WebspotBlogging Authentication Bypass Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16319",
          "name" : "16319",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0268",
          "name" : "ADV-2006-0268",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24222",
          "name" : "webspotblogging-login-sql-injection(24222)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://sourceforge.net/forum/forum.php?forum_id=532233",
          "name" : "https://sourceforge.net/forum/forum.php?forum_id=532233",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://sourceforge.net/project/shownotes.php?release_id=387180&group_id=156586",
          "name" : "https://sourceforge.net/project/shownotes.php?release_id=387180&group_id=156586",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in WebspotBlogging 3.0 allows remote attackers to execute arbitrary SQL commands and bypass authentication via the username parameter to login.php."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:webspot:webspotblogging:3.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-19T21:03Z",
    "lastModifiedDate" : "2018-10-19T15:44Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0325",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "etomite",
            "product" : {
              "product_data" : [ {
                "product_name" : "etomite",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.6",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-78"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18556",
          "name" : "18556",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.etomite.org/forums/index.php?showtopic=4185",
          "name" : "http://www.etomite.org/forums/index.php?showtopic=4185",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.etomite.org/forums/index.php?showtopic=4291",
          "name" : "http://www.etomite.org/forums/index.php?showtopic=4291",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.lucaercoli.it/advs/etomite.txt",
          "name" : "http://www.lucaercoli.it/advs/etomite.txt",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/22693",
          "name" : "22693",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/423497/100/0/threaded",
          "name" : "20060127 Etomite CMS \"Backdoored\"",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/423523/100/0/threaded",
          "name" : "20060130 Etomite followup information",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16336",
          "name" : "16336",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0283",
          "name" : "ADV-2006-0283",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24254",
          "name" : "etomite-default-backdoor(24254)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Etomite Content Management System 0.6, and possibly earlier versions, when downloaded from the web site in January 2006 after January 10, contains a back door in manager/includes/todo.inc.php, which allows remote attackers to execute arbitrary commands via the \"cij\" parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:etomite:etomite:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "0.6"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-20T21:03Z",
    "lastModifiedDate" : "2018-10-19T15:44Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0327",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "typo3",
            "product" : {
              "product_data" : [ {
                "product_name" : "typo3",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.7.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.8.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://bugs.typo3.org/view.php?id=2248",
          "name" : "http://bugs.typo3.org/view.php?id=2248",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18546",
          "name" : "18546",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/361",
          "name" : "361",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.irmplc.com/advisory015.htm",
          "name" : "http://www.irmplc.com/advisory015.htm",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/22665",
          "name" : "22665",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/22666",
          "name" : "22666",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/22667",
          "name" : "22667",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/422360/100/0/threaded",
          "name" : "20060119 IRM 015: File system path disclosure on TYPO3 Web Content Manager",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/422390/100/0/threaded",
          "name" : "20060119 Re: IRM 015: File system path disclosure on TYPO3 Web Content Manager",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0269",
          "name" : "ADV-2006-0269",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24244",
          "name" : "typo3-multiple-path-disclosure(24244)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "TYPO3 3.7.1 allows remote attackers to obtain sensitive information via a direct request to (1) thumbs.php, (2) showpic.php, or (3) tables.php, which causes them to incorrectly define a variable and reveal the path in an error message when a require function call fails."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:typo3:typo3:3.7.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:typo3:typo3:3.8.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-21T00:03Z",
    "lastModifiedDate" : "2018-10-19T15:44Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0328",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "philippe_jounin",
            "product" : {
              "product_data" : [ {
                "product_name" : "tftpd32",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.81",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18539",
          "name" : "18539",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/362",
          "name" : "362",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.critical.lt/?vulnerabilities/200",
          "name" : "http://www.critical.lt/?vulnerabilities/200",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://www.critical.lt/research/tftpd32_281_dos.txt",
          "name" : "http://www.critical.lt/research/tftpd32_281_dos.txt",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/632633",
          "name" : "VU#632633",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.osvdb.org/22661",
          "name" : "22661",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/422405/100/0/threaded",
          "name" : "20060119 Critical security advisory #006 tftpd32 Format string",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16333",
          "name" : "16333",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0263",
          "name" : "ADV-2006-0263",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24250",
          "name" : "tftpd32-request-format-string(24250)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Format string vulnerability in Tftpd32 2.81 allows remote attackers to cause a denial of service via format string specifiers in a filename in a (1) GET or (2) SEND request."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:philippe_jounin:tftpd32:2.81:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-21T00:03Z",
    "lastModifiedDate" : "2018-10-19T15:44Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0329",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "hitachi",
            "product" : {
              "product_data" : [ {
                "product_name" : "hitsenser_data_mart_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "bs",
                    "version_affected" : "="
                  }, {
                    "version_value" : "bs_l",
                    "version_affected" : "="
                  }, {
                    "version_value" : "bs_m",
                    "version_affected" : "="
                  }, {
                    "version_value" : "bs_s",
                    "version_affected" : "="
                  }, {
                    "version_value" : "ex",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18553",
          "name" : "18553",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1015519",
          "name" : "1015519",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.hitachi-support.com/security_e/vuls_e/HS05-026_e/index-e.html",
          "name" : "http://www.hitachi-support.com/security_e/vuls_e/HS05-026_e/index-e.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/22669",
          "name" : "22669",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16326",
          "name" : "16326",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0266",
          "name" : "ADV-2006-0266",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24240",
          "name" : "hitachi-hitsenser-sql-injection(24240)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in HITSENSER Data Mart Server BS, BS-S, BS-M, BS-L, and EX allows remote attackers to execute arbitrary SQL commands via unknown attack vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hitachi:hitsenser_data_mart_server:bs:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hitachi:hitsenser_data_mart_server:bs_l:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hitachi:hitsenser_data_mart_server:bs_m:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hitachi:hitsenser_data_mart_server:bs_s:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hitachi:hitsenser_data_mart_server:ex:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-21T00:03Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0330",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "gallery_project",
            "product" : {
              "product_data" : [ {
                "product_name" : "gallery",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.3.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.3_pl1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.3_pl2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.4_pl2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.4_pl3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.4_pl4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.4_pl5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4_pl1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4_pl2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.1_rc2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.2_rc2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=325285",
          "name" : "http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=325285",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://gallery.menalto.com/page/gallery_1_5_2_release",
          "name" : "http://gallery.menalto.com/page/gallery_1_5_2_release",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18557",
          "name" : "18557",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18627",
          "name" : "18627",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/21502",
          "name" : "21502",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.gentoo.org/security/en/glsa/glsa-200601-13.xml",
          "name" : "GLSA-200601-13",
          "refsource" : "GENTOO",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/22660",
          "name" : "22660",
          "refsource" : "OSVDB",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16334",
          "name" : "16334",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.us.debian.org/security/2006/dsa-1148",
          "name" : "DSA-1148",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0282",
          "name" : "ADV-2006-0282",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24247",
          "name" : "gallery-unknown-xss(24247)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in Gallery before 1.5.2 allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors, possibly involving the user name (fullname)."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:gallery_project:gallery:1.3.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:gallery_project:gallery:1.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:gallery_project:gallery:1.4.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:gallery_project:gallery:1.4.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:gallery_project:gallery:1.4.3_pl1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:gallery_project:gallery:1.4.3_pl2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:gallery_project:gallery:1.4.4_pl2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:gallery_project:gallery:1.4.4_pl3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:gallery_project:gallery:1.4.4_pl4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:gallery_project:gallery:1.4.4_pl5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:gallery_project:gallery:1.4_pl1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:gallery_project:gallery:1.4_pl2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:gallery_project:gallery:1.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:gallery_project:gallery:1.5.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:gallery_project:gallery:1.5.1_rc2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:gallery_project:gallery:1.5.2_rc2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-21T00:03Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0331",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "thiago_melo_de_paula",
            "product" : {
              "product_data" : [ {
                "product_name" : "change_passwd",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://securityreason.com/securityalert/363",
          "name" : "363",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/422414/100/0/threaded",
          "name" : "20060119 Change passwd 3.1 (SquirrelMail plugin )",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.squirrelmail.org/plugin_view.php?id=117",
          "name" : "http://www.squirrelmail.org/plugin_view.php?id=117",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24258",
          "name" : "changepassword-changepasswd-bo(24258)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Buffer overflow in Change passwd 3.1 (chpasswd) SquirrelMail plugin allows local users to execute arbitrary code via long command line arguments."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:thiago_melo_de_paula:change_passwd:3.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 4.6
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 3.9,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-21T00:03Z",
    "lastModifiedDate" : "2018-10-19T15:44Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0332",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ecartis",
            "product" : {
              "product_data" : [ {
                "product_name" : "ecartis",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0.0_snapshot_2005-09-09",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-94"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://marc.info/?l=listar-dev&m=113732552708625&w=2",
          "name" : "[listar-dev] 20060115 [EDev] Re: Potential vulnerability -- who to contact?",
          "refsource" : "MLIST",
          "tags" : [ ]
        }, {
          "url" : "http://marc.info/?l=listar-dev&m=113770802408358&w=2",
          "name" : "[listar-dev] 20060119 [EDev] Re: Potential vulnerability -- who to contact?",
          "refsource" : "MLIST",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18524",
          "name" : "18524",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16317",
          "name" : "16317",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0260",
          "name" : "ADV-2006-0260",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24220",
          "name" : "ecartis-pantomime-bypass-security(24220)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Pantomime in Ecartis 1.0.0 snapshot 20050909 stores e-mail attachments in a publicly accessible directory, which may allow remote attackers to upload arbitrary files."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ecartis:ecartis:1.0.0_snapshot_2005-09-09:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 6.4
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-21T00:03Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0333",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ar-blog",
            "product" : {
              "product_data" : [ {
                "product_name" : "ar-blog",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/archive/1/422386/100/0/threaded",
          "name" : "20060118 -2- [XSS] in ar-blog v 5.2",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/435205/100/0/threaded",
          "name" : "20060527 Multiple Xss exploits in ar-blog v 5.2",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24246",
          "name" : "arblog-index-xss(24246)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in ar-blog 5.2 allows remote attackers to inject arbitrary web script or HTML via the (1) month or (2) year parameter to index.php."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ar-blog:ar-blog:5.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-21T00:03Z",
    "lastModifiedDate" : "2018-10-19T15:44Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0334",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "freekrai.net",
            "product" : {
              "product_data" : [ {
                "product_name" : "my_amazon_store_manager",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/ref/22/22626-my_amazon.txt",
          "name" : "http://osvdb.org/ref/22/22626-my_amazon.txt",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://secunia.com/advisories/18535",
          "name" : "18535",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/22626",
          "name" : "22626",
          "refsource" : "OSVDB",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16312",
          "name" : "16312",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0252",
          "name" : "ADV-2006-0252",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24230",
          "name" : "masm-search-xss(24230)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in search.php in My Amazon Store Manager 1.0 allows remote attackers to inject arbitrary web script or HTML via the Keywords parameter.  NOTE: some sources claim that the affected parameter is \"q\", but the only public archive of the original researcher notification shows an XSS manipulation in \"Keywords\"."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:freekrai.net:my_amazon_store_manager:1.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-21T00:03Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0335",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "kerio",
            "product" : {
              "product_data" : [ {
                "product_name" : "winroute_firewall",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.1.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.1.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.1.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.1.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.1.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.1.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.1.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.3_patch1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.4",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18542",
          "name" : "18542",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.kerio.com/kwf_history.html",
          "name" : "http://www.kerio.com/kwf_history.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/22631",
          "name" : "22631",
          "refsource" : "OSVDB",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16314",
          "name" : "16314",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0247",
          "name" : "ADV-2006-0247",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24232",
          "name" : "kerio-winroute-html-dos(24232)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24233",
          "name" : "kerio-winroute-activedirectory-dos(24233)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple unspecified vulnerabilities in Kerio WinRoute Firewall before 6.1.4 Patch 1 allow remote attackers to cause a denial of service via multiple unspecified vectors involving (1) long strings received from Active Directory and (2) the filtering of HTML."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:kerio:winroute_firewall:5.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:kerio:winroute_firewall:5.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:kerio:winroute_firewall:5.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:kerio:winroute_firewall:5.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:kerio:winroute_firewall:5.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:kerio:winroute_firewall:5.0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:kerio:winroute_firewall:5.0.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:kerio:winroute_firewall:5.0.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:kerio:winroute_firewall:5.0.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:kerio:winroute_firewall:5.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:kerio:winroute_firewall:5.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:kerio:winroute_firewall:5.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:kerio:winroute_firewall:5.1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:kerio:winroute_firewall:5.1.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:kerio:winroute_firewall:5.1.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:kerio:winroute_firewall:5.1.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:kerio:winroute_firewall:5.1.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:kerio:winroute_firewall:5.1.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:kerio:winroute_firewall:5.1.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:kerio:winroute_firewall:5.1.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:kerio:winroute_firewall:5.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:kerio:winroute_firewall:6.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:kerio:winroute_firewall:6.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:kerio:winroute_firewall:6.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:kerio:winroute_firewall:6.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:kerio:winroute_firewall:6.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:kerio:winroute_firewall:6.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:kerio:winroute_firewall:6.0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:kerio:winroute_firewall:6.0.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:kerio:winroute_firewall:6.0.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:kerio:winroute_firewall:6.0.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:kerio:winroute_firewall:6.0.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:kerio:winroute_firewall:6.0.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:kerio:winroute_firewall:6.1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:kerio:winroute_firewall:6.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:kerio:winroute_firewall:6.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:kerio:winroute_firewall:6.1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:kerio:winroute_firewall:6.1.3_patch1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:kerio:winroute_firewall:6.1.4:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-21T00:03Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0336",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "kerio",
            "product" : {
              "product_data" : [ {
                "product_name" : "winroute_firewall",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.1.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.1.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.1.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.1.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.1.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.1.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.1.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.3_patch1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.4_patch_1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18589",
          "name" : "18589",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.kerio.com/kwf_history.html",
          "name" : "http://www.kerio.com/kwf_history.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/22631",
          "name" : "22631",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16385",
          "name" : "16385",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0324",
          "name" : "ADV-2006-0324",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24317",
          "name" : "kerio-winroute-browsing-dos(24317)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Kerio WinRoute Firewall before 6.1.4 Patch 2 allows attackers to cause a denial of service (CPU consumption and hang) via unknown vectors involving \"browsing the web\"."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:kerio:winroute_firewall:5.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:kerio:winroute_firewall:5.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:kerio:winroute_firewall:5.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:kerio:winroute_firewall:5.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:kerio:winroute_firewall:5.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:kerio:winroute_firewall:5.0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:kerio:winroute_firewall:5.0.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:kerio:winroute_firewall:5.0.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:kerio:winroute_firewall:5.0.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:kerio:winroute_firewall:5.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:kerio:winroute_firewall:5.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:kerio:winroute_firewall:5.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:kerio:winroute_firewall:5.1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:kerio:winroute_firewall:5.1.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:kerio:winroute_firewall:5.1.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:kerio:winroute_firewall:5.1.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:kerio:winroute_firewall:5.1.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:kerio:winroute_firewall:5.1.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:kerio:winroute_firewall:5.1.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:kerio:winroute_firewall:5.1.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:kerio:winroute_firewall:5.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:kerio:winroute_firewall:6.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:kerio:winroute_firewall:6.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:kerio:winroute_firewall:6.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:kerio:winroute_firewall:6.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:kerio:winroute_firewall:6.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:kerio:winroute_firewall:6.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:kerio:winroute_firewall:6.0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:kerio:winroute_firewall:6.0.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:kerio:winroute_firewall:6.0.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:kerio:winroute_firewall:6.0.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:kerio:winroute_firewall:6.0.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:kerio:winroute_firewall:6.0.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:kerio:winroute_firewall:6.1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:kerio:winroute_firewall:6.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:kerio:winroute_firewall:6.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:kerio:winroute_firewall:6.1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:kerio:winroute_firewall:6.1.3_patch1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:kerio:winroute_firewall:6.1.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:kerio:winroute_firewall:6.1.4_patch_1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-21T00:03Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0337",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "f-secure",
            "product" : {
              "product_data" : [ {
                "product_name" : "f-secure_anti-virus",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.16",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.51",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.52",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.61",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.62",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.64",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.01",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.40",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.41",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.42",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.43",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.44",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.51",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.52",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.54",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.55",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.61",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.01",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.21",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.30",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.30_sr1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.31",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.40",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2004",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2005",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2006",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "f-secure_internet_security",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2004",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2005",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2006",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "internet_gatekeeper",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.06",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.31",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.32",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.41",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.42",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "solutions_based_on_f-secure_personal_express",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.20",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18529",
          "name" : "18529",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1015507",
          "name" : "1015507",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1015508",
          "name" : "1015508",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1015509",
          "name" : "1015509",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1015510",
          "name" : "1015510",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.ciac.org/ciac/bulletins/q-103.shtml",
          "name" : "Q-103",
          "refsource" : "CIAC",
          "tags" : [ ]
        }, {
          "url" : "http://www.f-secure.com/security/fsc-2006-1.shtml",
          "name" : "http://www.f-secure.com/security/fsc-2006-1.shtml",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/22632",
          "name" : "22632",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16309",
          "name" : "16309",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0257",
          "name" : "ADV-2006-0257",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24198",
          "name" : "fsecure-zip-bo(24198)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Buffer overflow in multiple F-Secure Anti-Virus products and versions for Windows and Linux, including Anti-Virus for Windows Servers 5.52 and earlier, Internet Security 2004, 2005 and 2006, and Anti-Virus for Linux Servers 4.64 and earlier, allows remote attackers to execute arbitrary code via crafted ZIP archives."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:f-secure:f-secure_anti-virus:2.16:*:linux_gateways:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:f-secure:f-secure_anti-virus:4.51:*:linux_gateways:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:f-secure:f-secure_anti-virus:4.51:*:linux_servers:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:f-secure:f-secure_anti-virus:4.51:*:linux_workstations:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:f-secure:f-secure_anti-virus:4.52:*:linux_gateways:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:f-secure:f-secure_anti-virus:4.52:*:linux_servers:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:f-secure:f-secure_anti-virus:4.52:*:linux_workstations:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:f-secure:f-secure_anti-virus:4.61:*:linux_gateways:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:f-secure:f-secure_anti-virus:4.61:*:linux_servers:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:f-secure:f-secure_anti-virus:4.62:*:samba_servers:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:f-secure:f-secure_anti-virus:4.64:*:linux_gateways:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:f-secure:f-secure_anti-virus:4.64:*:linux_servers:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:f-secure:f-secure_anti-virus:5.0:*:linux_client_security:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:f-secure:f-secure_anti-virus:5.0:*:linux_server_security:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:f-secure:f-secure_anti-virus:5.01:*:linux_client_security:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:f-secure:f-secure_anti-virus:5.01:*:linux_server_security:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:f-secure:f-secure_anti-virus:5.5:*:citrix_servers:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:f-secure:f-secure_anti-virus:5.5:*:client_security:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:f-secure:f-secure_anti-virus:5.5:*:mimesweeper:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:f-secure:f-secure_anti-virus:5.5:*:windows_servers:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:f-secure:f-secure_anti-virus:5.11:*:linux_client_security:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:f-secure:f-secure_anti-virus:5.11:*:linux_server_security:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:f-secure:f-secure_anti-virus:5.40:*:workstations:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:f-secure:f-secure_anti-virus:5.41:*:mimesweeper:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:f-secure:f-secure_anti-virus:5.41:*:windows_servers:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:f-secure:f-secure_anti-virus:5.41:*:workstations:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:f-secure:f-secure_anti-virus:5.42:*:mimesweeper:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:f-secure:f-secure_anti-virus:5.42:*:windows_servers:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:f-secure:f-secure_anti-virus:5.42:*:workstations:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:f-secure:f-secure_anti-virus:5.43:*:workstations:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:f-secure:f-secure_anti-virus:5.44:*:workstations:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:f-secure:f-secure_anti-virus:5.51:*:mimesweeper:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:f-secure:f-secure_anti-virus:5.52:*:citrix_servers:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:f-secure:f-secure_anti-virus:5.52:*:client_security:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:f-secure:f-secure_anti-virus:5.52:*:windows_servers:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:f-secure:f-secure_anti-virus:5.54:*:client_security:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:f-secure:f-secure_anti-virus:5.55:*:client_security:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:f-secure:f-secure_anti-virus:5.61:*:mimesweeper:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:f-secure:f-secure_anti-virus:6.01:*:client_security:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:f-secure:f-secure_anti-virus:6.01:*:ms_exchange:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:f-secure:f-secure_anti-virus:6.2:*:firewalls:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:f-secure:f-secure_anti-virus:6.2:*:ms_exchange:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:f-secure:f-secure_anti-virus:6.21:*:ms_exchange:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:f-secure:f-secure_anti-virus:6.30:*:ms_exchange:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:f-secure:f-secure_anti-virus:6.30_sr1:*:ms_exchange:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:f-secure:f-secure_anti-virus:6.31:*:ms_exchange:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:f-secure:f-secure_anti-virus:6.40:*:ms_exchange:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:f-secure:f-secure_anti-virus:2004:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:f-secure:f-secure_anti-virus:2005:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:f-secure:f-secure_anti-virus:2006:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:f-secure:f-secure_internet_security:2004:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:f-secure:f-secure_internet_security:2005:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:f-secure:f-secure_internet_security:2006:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:f-secure:internet_gatekeeper:2.06:*:linux:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:f-secure:internet_gatekeeper:2.6:*:linux:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:f-secure:internet_gatekeeper:2.14:*:linux:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:f-secure:internet_gatekeeper:6.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:f-secure:internet_gatekeeper:6.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:f-secure:internet_gatekeeper:6.31:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:f-secure:internet_gatekeeper:6.32:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:f-secure:internet_gatekeeper:6.41:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:f-secure:internet_gatekeeper:6.42:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:f-secure:solutions_based_on_f-secure_personal_express:6.20:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-21T00:03Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0338",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "f-secure",
            "product" : {
              "product_data" : [ {
                "product_name" : "f-secure_anti-virus",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.51",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.52",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.60",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.61",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.62",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.64",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.41",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.42",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.43",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.44",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.52",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.55",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.01",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.21",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.30",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.30_sr1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.31",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.40",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2003",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2004",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2005",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "f-secure_internet_security",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2004",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2005",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2006",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "f-secure_personal_express",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "internet_gatekeeper",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.06",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.32",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.41",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.42",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18529",
          "name" : "18529",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1015507",
          "name" : "1015507",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1015508",
          "name" : "1015508",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1015509",
          "name" : "1015509",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1015510",
          "name" : "1015510",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.ciac.org/ciac/bulletins/q-103.shtml",
          "name" : "Q-103",
          "refsource" : "CIAC",
          "tags" : [ ]
        }, {
          "url" : "http://www.f-secure.com/security/fsc-2006-1.shtml",
          "name" : "http://www.f-secure.com/security/fsc-2006-1.shtml",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.osvdb.org/22633",
          "name" : "22633",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16309",
          "name" : "16309",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0257",
          "name" : "ADV-2006-0257",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24199",
          "name" : "fsecure-rar-zip-scan-bypass(24199)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple F-Secure Anti-Virus products and versions for Windows and Linux, including Anti-Virus for Windows Servers 5.52 and earlier, Internet Security 2004, 2005 and 2006, and Anti-Virus for Linux Servers 4.64 and earlier, allow remote attackers to hide arbitrary files and data via malformed (1) RAR and (2) ZIP archives, which are not properly scanned."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:f-secure:f-secure_anti-virus:4.51:*:linux_gateways:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:f-secure:f-secure_anti-virus:4.51:*:linux_servers:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:f-secure:f-secure_anti-virus:4.52:*:linux_gateways:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:f-secure:f-secure_anti-virus:4.52:*:linux_servers:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:f-secure:f-secure_anti-virus:4.52:*:linux_workstations:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:f-secure:f-secure_anti-virus:4.60:*:samba_servers:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:f-secure:f-secure_anti-virus:4.61:*:linux_gateways:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:f-secure:f-secure_anti-virus:4.61:*:linux_servers:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:f-secure:f-secure_anti-virus:4.62:*:samba_servers:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:f-secure:f-secure_anti-virus:4.64:*:linux_gateways:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:f-secure:f-secure_anti-virus:4.64:*:linux_servers:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:f-secure:f-secure_anti-virus:5.0:*:linux_client_security:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:f-secure:f-secure_anti-virus:5.0:*:linux_server_security:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:f-secure:f-secure_anti-virus:5.5:*:client_security:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:f-secure:f-secure_anti-virus:5.5:*:mimesweeper:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:f-secure:f-secure_anti-virus:5.5:*:windows_servers:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:f-secure:f-secure_anti-virus:5.11:*:linux_client_security:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:f-secure:f-secure_anti-virus:5.11:*:linux_server_security:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:f-secure:f-secure_anti-virus:5.41:*:mimesweeper:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:f-secure:f-secure_anti-virus:5.41:*:workstations:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:f-secure:f-secure_anti-virus:5.42:*:mimesweeper:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:f-secure:f-secure_anti-virus:5.42:*:windows_servers:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:f-secure:f-secure_anti-virus:5.42:*:workstations:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:f-secure:f-secure_anti-virus:5.43:*:workstations:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:f-secure:f-secure_anti-virus:5.44:*:workstations:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:f-secure:f-secure_anti-virus:5.52:*:citrix_servers:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:f-secure:f-secure_anti-virus:5.52:*:client_security:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:f-secure:f-secure_anti-virus:5.52:*:mimesweeper:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:f-secure:f-secure_anti-virus:5.52:*:windows_servers:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:f-secure:f-secure_anti-virus:5.55:*:client_security:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:f-secure:f-secure_anti-virus:6.01:*:client_security:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:f-secure:f-secure_anti-virus:6.01:*:ms_exchange:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:f-secure:f-secure_anti-virus:6.2:*:firewalls:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:f-secure:f-secure_anti-virus:6.2:*:ms_exchange:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:f-secure:f-secure_anti-virus:6.21:*:ms_exchange:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:f-secure:f-secure_anti-virus:6.30:*:ms_exchange:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:f-secure:f-secure_anti-virus:6.30_sr1:*:ms_exchange:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:f-secure:f-secure_anti-virus:6.31:*:ms_exchange:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:f-secure:f-secure_anti-virus:6.40:*:ms_exchange:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:f-secure:f-secure_anti-virus:2003:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:f-secure:f-secure_anti-virus:2004:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:f-secure:f-secure_anti-virus:2005:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:f-secure:f-secure_internet_security:2004:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:f-secure:f-secure_internet_security:2005:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:f-secure:f-secure_internet_security:2006:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:f-secure:f-secure_personal_express:4.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:f-secure:f-secure_personal_express:4.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:f-secure:f-secure_personal_express:4.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:f-secure:f-secure_personal_express:5.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:f-secure:internet_gatekeeper:2.06:*:linux:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:f-secure:internet_gatekeeper:2.14:*:linux:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:f-secure:internet_gatekeeper:6.32:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:f-secure:internet_gatekeeper:6.41:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:f-secure:internet_gatekeeper:6.42:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-21T00:03Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0339",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "bitcomet",
            "product" : {
              "product_data" : [ {
                "product_name" : "bitcomet",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.60",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://archives.neohapsis.com/archives/bugtraq/2006-01/0442.html",
          "name" : "20060122 BitComet URI Proof of Concept",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://archives.neohapsis.com/archives/fulldisclosure/2006-01/0669.html",
          "name" : "20060118 Fortinet Advisory: BitComet URI Buffer Overflow Vulnerability",
          "refsource" : "FULLDISC",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18522",
          "name" : "18522",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/357",
          "name" : "357",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.bitcomet.com/doc/changelog.htm",
          "name" : "http://www.bitcomet.com/doc/changelog.htm",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.fortinet.com/FortiGuardCenter/FSA-2006-07.html",
          "name" : "http://www.fortinet.com/FortiGuardCenter/FSA-2006-07.html",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/22625",
          "name" : "22625",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/422361/100/0/threaded",
          "name" : "20060118 Fortinet Advisory: BitComet URI Buffer Overflow Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16311",
          "name" : "16311",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0251",
          "name" : "ADV-2006-0251",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24229",
          "name" : "bitcomet-torrent-publisher-bo(24229)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Buffer overflow in BitComet Client 0.60 allows remote attackers to execute arbitrary code, when the publisher's name link is clicked, via a long publisher URI in a torrent file."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bitcomet:bitcomet:0.60:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-21T00:03Z",
    "lastModifiedDate" : "2018-10-19T15:44Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0340",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "cisco",
            "product" : {
              "product_data" : [ {
                "product_name" : "ios",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "12.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.0s",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.0sc",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.0t",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.0xa",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.0xc",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.0xd",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.0xe",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.0xg",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.0xh",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.0xi",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.0xj",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.0xk",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.0xl",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.0xn",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.0xr",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1aa",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1e",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1ec",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1ex",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1ez",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1ga",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1gb",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1t",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1xa",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1xd",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1xh",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1xi",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1xl",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1xm",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1xq",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1xs",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1xu",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1xw",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1xx",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1xy",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1xz",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1ya",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1yb",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1yd",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2b",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2bc",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2bw",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2by",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2cx",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2dd",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2dx",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2mc",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2s",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2su",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2sy",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2sz",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2t",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2xa",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2xb",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2xc",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2xf",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2xg",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2xk",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2xl",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2xs",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2xt",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2xv",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2yd",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2ye",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2yn",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2yt",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2yw",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2yx",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2yy",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2yz",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2za",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2zb",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2zd",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2ze",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2zj",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2zn",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3b",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3bc",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3bw",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3t",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3xb",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3xd",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3xf",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3xh",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3xi",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3xj",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3xm",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3xq",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3xu",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3xw",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3yf",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3yg",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3yj",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3yk",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3ym",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3yq",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3yt",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3yu",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3yx",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.4mr",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.4t",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.4xa",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.4xb",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-20"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18490",
          "name" : "18490",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/358",
          "name" : "358",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1015501",
          "name" : "1015501",
          "refsource" : "SECTRACK",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.cisco.com/warp/public/707/cisco-sa-20060118-sgbp.shtml",
          "name" : "20060118 IOS Stack Group Bidding Protocol Crafted Packet DoS",
          "refsource" : "CISCO",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/22624",
          "name" : "22624",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16303",
          "name" : "16303",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0248",
          "name" : "ADV-2006-0248",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24182",
          "name" : "cisco-ios-sgbp-dos(24182)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in Stack Group Bidding Protocol (SGBP) support in Cisco IOS 12.0 through 12.4 running on various Cisco products, when SGBP is enabled, allows remote attackers on the local network to cause a denial of service (device hang and network traffic loss) via a crafted UDP packet to port 9900."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.0s:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.0sc:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.0t:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.0xa:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.0xc:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.0xd:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.0xe:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.0xg:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.0xh:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.0xi:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.0xj:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.0xk:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.0xl:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.0xn:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.0xr:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.1aa:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.1e:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.1ec:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.1ex:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.1ez:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.1ga:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.1gb:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.1t:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.1xa:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.1xd:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.1xh:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.1xi:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.1xl:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.1xm:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.1xq:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.1xs:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.1xu:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.1xw:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.1xx:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.1xy:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.1xz:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.1ya:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.1yb:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.1yd:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.2b:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.2bc:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.2bw:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.2by:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.2cx:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.2dd:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.2dx:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.2mc:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.2s:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.2su:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.2sy:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.2sz:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.2t:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.2xa:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.2xb:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.2xc:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.2xf:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.2xg:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.2xk:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.2xl:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.2xs:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.2xt:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.2xv:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.2yd:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.2ye:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.2yn:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.2yt:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.2yw:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.2yx:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.2yy:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.2yz:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.2za:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.2zb:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.2zd:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.2ze:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.2zj:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.2zn:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.3b:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.3bc:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.3bw:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.3t:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.3xb:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.3xd:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.3xf:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.3xh:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.3xi:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.3xj:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.3xm:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.3xq:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.3xu:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.3xw:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.3yf:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.3yg:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.3yj:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.3yk:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.3ym:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.3yq:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.3yt:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.3yu:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.3yx:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.4mr:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.4t:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.4xa:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.4xb:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:N/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.1
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-21T00:03Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0341",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "rockliffe",
            "product" : {
              "product_data" : [ {
                "product_name" : "mailsite",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.1.22",
                    "version_affected" : "<="
                  }, {
                    "version_value" : "7.0.3.1",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://marc.info/?l=full-disclosure&m=113777628702043&w=2",
          "name" : "20060120 RockLiffe MailSite wconsole.dll Denial of Service/Script Injection Vulnerability",
          "refsource" : "FULLDISC",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18551",
          "name" : "18551",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/22677",
          "name" : "22677",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16330",
          "name" : "16330",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0284",
          "name" : "ADV-2006-0284",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24256",
          "name" : "mailsite-wconsole-xss(24256)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in WCONSOLE.DLL in Rockliffe MailSite 5.x and 6.1.22 and earlier allows remote attackers to inject arbitrary web script or HTML via the query string."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rockliffe:mailsite:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "6.1.22"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rockliffe:mailsite:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "7.0.3.1"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-06T05:00Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0342",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "rockliffe",
            "product" : {
              "product_data" : [ {
                "product_name" : "mailsite",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.0.3.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-399"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://marc.info/?l=full-disclosure&m=113777628702043&w=2",
          "name" : "20060120 RockLiffe MailSite wconsole.dll Denial of Service/Script Injection Vulnerability",
          "refsource" : "FULLDISC",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18551",
          "name" : "18551",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/22678",
          "name" : "22678",
          "refsource" : "OSVDB",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16331",
          "name" : "16331",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0284",
          "name" : "ADV-2006-0284",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24255",
          "name" : "mailsite-wconsole-dos(24255)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "RockLiffe MailSite HTTP Mail management agent (httpma) 7.0.3.1 allows remote attackers to cause a denial of service (CPU consumption and crash) via a malformed query string containing special characters such as \"|\"."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rockliffe:mailsite:7.0.3.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.8
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-21T00:03Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0343",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "hitachi",
            "product" : {
              "product_data" : [ {
                "product_name" : "jpi_netsight_ii_port_discovery_advance",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "r_15237_9154_07_50",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "jpi_netsight_ii_port_discovery_standard",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "r_15237_9164_07_00",
                    "version_affected" : "="
                  }, {
                    "version_value" : "r_15237_9164_07_01",
                    "version_affected" : "="
                  }, {
                    "version_value" : "r_15237_9164_07_02",
                    "version_affected" : "="
                  }, {
                    "version_value" : "r_15237_9164_07_03",
                    "version_affected" : "="
                  }, {
                    "version_value" : "r_15237_9164_07_04",
                    "version_affected" : "="
                  }, {
                    "version_value" : "r_15237_9164_07_05",
                    "version_affected" : "="
                  }, {
                    "version_value" : "r_15237_9164_07_06",
                    "version_affected" : "="
                  }, {
                    "version_value" : "r_15237_9164_07_07",
                    "version_affected" : "="
                  }, {
                    "version_value" : "r_15237_9164_07_08",
                    "version_affected" : "="
                  }, {
                    "version_value" : "r_15237_9164_07_09",
                    "version_affected" : "="
                  }, {
                    "version_value" : "r_15237_9164_07_10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "r_15237_9164_07_11",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18538",
          "name" : "18538",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1015520",
          "name" : "1015520",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.hitachi-support.com/security_e/vuls_e/HS05-027_e/index-e.html",
          "name" : "http://www.hitachi-support.com/security_e/vuls_e/HS05-027_e/index-e.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/22676",
          "name" : "22676",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16327",
          "name" : "16327",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0267",
          "name" : "ADV-2006-0267",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24243",
          "name" : "hitachi-jp1netinsight-port-dos(24243)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Port Discovery Standard and Advanced features in Hitachi JP1/NetInsight II allows attackers to stop the Port Discovery service via unknown vectors involving \"invalid format data\"."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hitachi:jpi_netsight_ii_port_discovery_advance:r_15237_9154_07_50:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hitachi:jpi_netsight_ii_port_discovery_standard:r_15237_9164_07_00:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hitachi:jpi_netsight_ii_port_discovery_standard:r_15237_9164_07_01:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hitachi:jpi_netsight_ii_port_discovery_standard:r_15237_9164_07_02:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hitachi:jpi_netsight_ii_port_discovery_standard:r_15237_9164_07_03:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hitachi:jpi_netsight_ii_port_discovery_standard:r_15237_9164_07_04:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hitachi:jpi_netsight_ii_port_discovery_standard:r_15237_9164_07_05:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hitachi:jpi_netsight_ii_port_discovery_standard:r_15237_9164_07_06:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hitachi:jpi_netsight_ii_port_discovery_standard:r_15237_9164_07_07:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hitachi:jpi_netsight_ii_port_discovery_standard:r_15237_9164_07_08:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hitachi:jpi_netsight_ii_port_discovery_standard:r_15237_9164_07_09:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hitachi:jpi_netsight_ii_port_discovery_standard:r_15237_9164_07_10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hitachi:jpi_netsight_ii_port_discovery_standard:r_15237_9164_07_11:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-21T00:03Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0344",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "intervations",
            "product" : {
              "product_data" : [ {
                "product_name" : "filecopa",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.01",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18550",
          "name" : "18550",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.nii.co.in/vuln/filecopa.html",
          "name" : "http://www.nii.co.in/vuln/filecopa.html",
          "refsource" : "MISC",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/22694",
          "name" : "22694",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16335",
          "name" : "16335",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0285",
          "name" : "ADV-2006-0285",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24257",
          "name" : "filecopa-ftp-directory-traversal(24257)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Directory traversal vulnerability in Intervations FileCOPA FTP Server 1.01 allows remote attackers to read and write arbitrary files via a .. (dot dot) in the (1) STOR and (2) RETR commands."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:intervations:filecopa:1.01:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 6.4
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-21T00:03Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0345",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "saral_kaushik",
            "product" : {
              "product_data" : [ {
                "product_name" : "saralblog",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://archives.neohapsis.com/archives/bugtraq/2006-01/0372.html",
          "name" : "20060118 [eVuln] SaralBlog XSS & Multiple SQL Injection Vulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://evuln.com/vulns/40/summary.html",
          "name" : "http://evuln.com/vulns/40/summary.html",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1015517",
          "name" : "1015517",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/22740",
          "name" : "22740",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16306",
          "name" : "16306",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24218",
          "name" : "saralblog-search-sql-injection(24218)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple SQL injection vulnerabilities in SaralBlog 1.0 allow remote attackers to execute arbitrary SQL commands via the search parameter to search.php.  NOTE: the id/viewprofile.php issue is already covered by CVE-2005-4058."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:saral_kaushik:saralblog:1.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-21T01:03Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0346",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "saral_kaushik",
            "product" : {
              "product_data" : [ {
                "product_name" : "saralblog",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://archives.neohapsis.com/archives/bugtraq/2006-01/0372.html",
          "name" : "20060118 [eVuln] SaralBlog XSS & Multiple SQL Injection Vulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://evuln.com/vulns/40/summary.html",
          "name" : "http://evuln.com/vulns/40/summary.html",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1015517",
          "name" : "1015517",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/27907",
          "name" : "27907",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16306",
          "name" : "16306",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24219",
          "name" : "saralblog-view-xss(24219)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in SaralBlog 1.0 allows remote attackers to inject arbitrary web script or HTML via a website field in a new comment to view.php, which is not properly handled in the comment function in functions.php."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:saral_kaushik:saralblog:1.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-21T01:03Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0347",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "stefan_ritt",
            "product" : {
              "product_data" : [ {
                "product_name" : "elog_web_logbook",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.5.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.5.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://midas.psi.ch/elog/download/ChangeLog",
          "name" : "http://midas.psi.ch/elog/download/ChangeLog",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18533",
          "name" : "18533",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18783",
          "name" : "18783",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2006/dsa-967",
          "name" : "DSA-967",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/22647",
          "name" : "22647",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16315",
          "name" : "16315",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0262",
          "name" : "ADV-2006-0262",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24224",
          "name" : "elog-dotdot-directory-traversal(24224)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Directory traversal vulnerability in ELOG before 2.6.1 allows remote attackers to access arbitrary files outside of the elog directory via \"../\" (dot dot) sequences in the URL."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:stefan_ritt:elog_web_logbook:2.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:stefan_ritt:elog_web_logbook:2.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:stefan_ritt:elog_web_logbook:2.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:stefan_ritt:elog_web_logbook:2.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:stefan_ritt:elog_web_logbook:2.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:stefan_ritt:elog_web_logbook:2.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:stefan_ritt:elog_web_logbook:2.1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:stefan_ritt:elog_web_logbook:2.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:stefan_ritt:elog_web_logbook:2.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:stefan_ritt:elog_web_logbook:2.1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:stefan_ritt:elog_web_logbook:2.2.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:stefan_ritt:elog_web_logbook:2.2.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:stefan_ritt:elog_web_logbook:2.2.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:stefan_ritt:elog_web_logbook:2.2.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:stefan_ritt:elog_web_logbook:2.2.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:stefan_ritt:elog_web_logbook:2.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:stefan_ritt:elog_web_logbook:2.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:stefan_ritt:elog_web_logbook:2.5.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:stefan_ritt:elog_web_logbook:2.5.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:stefan_ritt:elog_web_logbook:2.6.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-21T01:03Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0348",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "stefan_ritt",
            "product" : {
              "product_data" : [ {
                "product_name" : "elog_web_logbook",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.5.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.5.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://midas.psi.ch/elog/download/ChangeLog",
          "name" : "http://midas.psi.ch/elog/download/ChangeLog",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18533",
          "name" : "18533",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18783",
          "name" : "18783",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2006/dsa-967",
          "name" : "DSA-967",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/22646",
          "name" : "22646",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16315",
          "name" : "16315",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0262",
          "name" : "ADV-2006-0262",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24221",
          "name" : "elog-elogd-format-string(24221)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Format string vulnerability in the write_logfile function in ELOG before 2.6.1 allows remote attackers to cause a denial of service (server crash) via unknown attack vectors.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:stefan_ritt:elog_web_logbook:2.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:stefan_ritt:elog_web_logbook:2.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:stefan_ritt:elog_web_logbook:2.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:stefan_ritt:elog_web_logbook:2.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:stefan_ritt:elog_web_logbook:2.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:stefan_ritt:elog_web_logbook:2.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:stefan_ritt:elog_web_logbook:2.1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:stefan_ritt:elog_web_logbook:2.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:stefan_ritt:elog_web_logbook:2.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:stefan_ritt:elog_web_logbook:2.1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:stefan_ritt:elog_web_logbook:2.2.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:stefan_ritt:elog_web_logbook:2.2.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:stefan_ritt:elog_web_logbook:2.2.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:stefan_ritt:elog_web_logbook:2.2.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:stefan_ritt:elog_web_logbook:2.2.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:stefan_ritt:elog_web_logbook:2.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:stefan_ritt:elog_web_logbook:2.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:stefan_ritt:elog_web_logbook:2.5.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:stefan_ritt:elog_web_logbook:2.5.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:stefan_ritt:elog_web_logbook:2.6.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-21T01:03Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0349",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "epic_designs",
            "product" : {
              "product_data" : [ {
                "product_name" : "eggblog",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://archives.neohapsis.com/archives/bugtraq/2006-01/0371.html",
          "name" : "20060118 [eVuln] eggblog Multiple SQL Injection & XSS Vulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://evuln.com/vulns/39/summary.html",
          "name" : "http://evuln.com/vulns/39/summary.html",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18212",
          "name" : "18212",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1015505",
          "name" : "1015505",
          "refsource" : "SECTRACK",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/22751",
          "name" : "22751",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16305",
          "name" : "16305",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24210",
          "name" : "eggblog-blog-sql-injection(24210)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in eggblog 2.0 allows remote attackers to execute arbitrary SQL commands via the id parameter to blog.php."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:epic_designs:eggblog:2.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-21T01:03Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0350",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "epic_designs",
            "product" : {
              "product_data" : [ {
                "product_name" : "eggblog",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://archives.neohapsis.com/archives/bugtraq/2006-01/0371.html",
          "name" : "20060118 [eVuln] eggblog Multiple SQL Injection & XSS Vulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://evuln.com/vulns/39/summary.html",
          "name" : "http://evuln.com/vulns/39/summary.html",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18212",
          "name" : "18212",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1015505",
          "name" : "1015505",
          "refsource" : "SECTRACK",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/22752",
          "name" : "22752",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16305",
          "name" : "16305",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24209",
          "name" : "eggblog-topic-xss(24209)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in eggblog 2.0 allow remote attackers to inject arbitrary web script or HTML via the message field to topic.php."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:epic_designs:eggblog:2.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-21T01:03Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0351",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "don_moore",
            "product" : {
              "product_data" : [ {
                "product_name" : "mydns",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.7.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.9.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.9.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.9.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.9.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.9.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.9.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.9.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.9.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.9.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.9.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.9.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.9.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.10.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.10.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.10.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.10.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.10.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.11.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://mydns.bboy.net/download/changelog.html",
          "name" : "http://mydns.bboy.net/download/changelog.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18532",
          "name" : "18532",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18641",
          "name" : "18641",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18653",
          "name" : "18653",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1015521",
          "name" : "1015521",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2006/dsa-963",
          "name" : "DSA-963",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.gentoo.org/security/en/glsa/glsa-200601-16.xml",
          "name" : "GLSA-200601-16",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/22636",
          "name" : "22636",
          "refsource" : "OSVDB",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16431",
          "name" : "16431",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0256",
          "name" : "ADV-2006-0256",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24228",
          "name" : "mydns-query-dos(24228)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified \"critical denial-of-service vulnerability\" in MyDNS before 1.1.0 has unknown impact and attack vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:don_moore:mydns:0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:don_moore:mydns:0.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:don_moore:mydns:0.7.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:don_moore:mydns:0.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:don_moore:mydns:0.8.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:don_moore:mydns:0.8.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:don_moore:mydns:0.8.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:don_moore:mydns:0.9.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:don_moore:mydns:0.9.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:don_moore:mydns:0.9.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:don_moore:mydns:0.9.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:don_moore:mydns:0.9.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:don_moore:mydns:0.9.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:don_moore:mydns:0.9.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:don_moore:mydns:0.9.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:don_moore:mydns:0.9.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:don_moore:mydns:0.9.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:don_moore:mydns:0.9.12:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:don_moore:mydns:0.9.13:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:don_moore:mydns:0.10.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:don_moore:mydns:0.10.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:don_moore:mydns:0.10.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:don_moore:mydns:0.10.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:don_moore:mydns:0.10.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:don_moore:mydns:0.11.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:don_moore:mydns:1.0.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-21T01:03Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0352",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "fluffington",
            "product" : {
              "product_data" : [ {
                "product_name" : "flog",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.01",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://evuln.com/vulns/38/summary/bt/",
          "name" : "http://evuln.com/vulns/38/summary/bt/",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/422268/100/0/threaded",
          "name" : "20060117 [eVuln] Flog Information Disclosure Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/456069/100/0/threaded",
          "name" : "20070105 Flog 1.1.2 Remote Admin Password Disclosure",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24193",
          "name" : "flog-data-directory-insecure(24193)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/31307",
          "name" : "flog-admin-info-disclosure(31307)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The default configuration of Fluffington FLog 1.01 installs users.0.dat under the web document root with insufficient access control, which might allow remote attackers to obtain sensitive information (login credentials) via a direct request.  NOTE: It was later reported that 1.1.2 is also affected."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:fluffington:flog:1.01:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:fluffington:flog:1.1.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-21T01:03Z",
    "lastModifiedDate" : "2018-10-19T15:44Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0353",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "gnu",
            "product" : {
              "product_data" : [ {
                "product_name" : "lsh",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-200"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.lysator.liu.se/pipermail/lsh-bugs/2006q1/000467.html",
          "name" : "[lsh-bugs] SECURITY: lshd leaks fd:s to user shells",
          "refsource" : "MLIST",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18564",
          "name" : "18564",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18623",
          "name" : "18623",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.debian.org/security/2006/dsa-956",
          "name" : "DSA-956",
          "refsource" : "DEBIAN",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/22695",
          "name" : "22695",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16357",
          "name" : "16357",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0301",
          "name" : "ADV-2006-0301",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24263",
          "name" : "lsh-file-descriptor-leak(24263)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "unix_random.c in lshd for lsh 2.0.1 leaks file descriptors related to the randomness generator, which allows local users to cause a denial of service by truncating the seed file, which prevents the server from starting, or obtain sensitive seed information that could be used to crack keys."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:gnu:lsh:2.0.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:P/I:N/A:P",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 3.6
        },
        "severity" : "LOW",
        "exploitabilityScore" : 3.9,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-22T19:03Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0354",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "cisco",
            "product" : {
              "product_data" : [ {
                "product_name" : "aironet_ap1100",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "aironet_ap1130ag",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "aironet_ap1200",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "aironet_ap1230ag",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "aironet_ap1240ag",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "aironet_ap1300",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "aironet_ap1400",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "aironet_ap350",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-399"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18430",
          "name" : "18430",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/339",
          "name" : "339",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1015483",
          "name" : "1015483",
          "refsource" : "SECTRACK",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.cisco.com/warp/public/707/cisco-sa-20060112-wireless.shtml",
          "name" : "20060112 Access Point Memory Exhaustion from ARP Attacks",
          "refsource" : "CISCO",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/22375",
          "name" : "22375",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16217",
          "name" : "16217",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0176",
          "name" : "ADV-2006-0176",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24086",
          "name" : "cisco-aironet-arp-dos(24086)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5680",
          "name" : "oval:org.mitre.oval:def:5680",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cisco IOS before 12.3-7-JA2 on Aironet Wireless Access Points (WAP) allows remote authenticated users to cause a denial of service (termination of packet passing or termination of client connections) by sending the management interface a large number of spoofed ARP packets, which creates a large ARP table that exhausts memory, aka Bug ID CSCsc16644."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:aironet_ap1100:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:aironet_ap1130ag:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:aironet_ap1200:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:aironet_ap1230ag:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:aironet_ap1240ag:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:aironet_ap1300:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:aironet_ap1400:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:aironet_ap350:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:A/AC:L/Au:S/C:N/I:N/A:C",
          "accessVector" : "ADJACENT_NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 5.5
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 5.1,
        "impactScore" : 6.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-22T20:03Z",
    "lastModifiedDate" : "2017-10-11T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0355",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "helmsman_research",
            "product" : {
              "product_data" : [ {
                "product_name" : "homeftp",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://securityreason.com/securityalert/350",
          "name" : "350",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.kapda.ir/advisory-202.html",
          "name" : "http://www.kapda.ir/advisory-202.html",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/421869/100/0/threaded",
          "name" : "20060114 [KAPDA::#21] - HomeFtp v1.1 Denial of Service",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16238",
          "name" : "16238",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24152",
          "name" : "homeftp-long-command-dos(24152)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Helmsman Research (aka CoolUtils) HomeFtp 1.1 allows remote attackers to cause an unspecified denial of service via a long USER command combined with a long PASS command and an NLST command."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:helmsman_research:homeftp:1.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-22T20:03Z",
    "lastModifiedDate" : "2018-10-19T15:44Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0356",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ari_pikivirta",
            "product" : {
              "product_data" : [ {
                "product_name" : "home_ftp_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0.7",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.kapda.ir/advisory-211.html",
          "name" : "http://www.kapda.ir/advisory-211.html",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/422033/100/0/threaded",
          "name" : "20060115 Homeftp r1.0.7 Denial of Service",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24227",
          "name" : "homeftpserver-long-command-dos(24227)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Ari Pikivirta Home Ftp Server 1.0.7 allows remote attackers to cause an unspecified denial of service via a long USER command combined with a long PASS command."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ari_pikivirta:home_ftp_server:1.0.7:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-22T20:03Z",
    "lastModifiedDate" : "2018-10-19T15:44Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0357",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "grant_averett",
            "product" : {
              "product_data" : [ {
                "product_name" : "cerberus_ftp_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.32",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.cerberusftp.com/cerberus-releasenotes.htm",
          "name" : "http://www.cerberusftp.com/cerberus-releasenotes.htm",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.kapda.ir/advisory-210.html",
          "name" : "http://www.kapda.ir/advisory-210.html",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/422162/100/0/threaded",
          "name" : "20060115 Cerberus FTP Server 2.32 Denial of Service",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24226",
          "name" : "cerberus-long-command-dos(24226)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Grant Averett Cerberus FTP Server 2.32, and possibly earlier versions, allows remote attackers to cause an unspecified denial of service via a long string that does not contain a valid FTP command."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:grant_averett:cerberus_ftp_server:2.32:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-22T20:03Z",
    "lastModifiedDate" : "2018-10-19T15:44Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0358",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "powerportal",
            "product" : {
              "product_data" : [ {
                "product_name" : "powerportal",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.1b",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3b",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/10172",
          "name" : "10172",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://web.archive.org/web/20050303003128/http://powerportal.sourceforge.net/",
          "name" : "http://web.archive.org/web/20050303003128/http://powerportal.sourceforge.net/",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/27957",
          "name" : "27957",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/27958",
          "name" : "27958",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/422151/100/0/threaded",
          "name" : "20060117 PowerPortal Cross-Site Scripting Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16279",
          "name" : "16279",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24196",
          "name" : "powerportal-search-index-xss(24196)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple SQL injection vulnerabilities in PowerPortal, possibly 1.1 beta through 1.3, allow remote attackers to execute arbitrary SQL commands via the search parameter in (1) index.php and (2) search.php. NOTE: This issue might overlap CVE-2004-0663.2."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:powerportal:powerportal:1.1b:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:powerportal:powerportal:1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:powerportal:powerportal:1.3b:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-22T20:03Z",
    "lastModifiedDate" : "2018-10-19T15:44Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0359",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "counterpath",
            "product" : {
              "product_data" : [ {
                "product_name" : "eyebeam_sip_softphone",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://blog.donews.com/zwell/archive/2006/01/17/698810.aspx",
          "name" : "http://blog.donews.com/zwell/archive/2006/01/17/698810.aspx",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18516",
          "name" : "18516",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/354",
          "name" : "354",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/422009/100/0/threaded",
          "name" : "20060116 CounterPath eyeBeam Handing SIP header Vulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/446573/100/0/threaded",
          "name" : "20060921 Re: CounterPath eyeBeam Handing SIP header Vulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16253",
          "name" : "16253",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0259",
          "name" : "ADV-2006-0259",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24181",
          "name" : "eyebeam-sip-header-bo(24181)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Buffer overflow in CounterPath eyeBeam SIP Softphone allows remote attackers to (1) cause a denial of service (device crash) via SIP INVITE commands with a long header field name sent during startup and (2) cause a denial of service (device hang or crash) via SIP INVITE commands with a long header field name sent during a call."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:counterpath:eyebeam_sip_softphone:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-22T20:03Z",
    "lastModifiedDate" : "2018-10-19T15:44Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0360",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "mpm",
            "product" : {
              "product_data" : [ {
                "product_name" : "hp-180w_voip_wifi_phone",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "we.00.17",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.grok.org.uk/pipermail/full-disclosure/2006-January/041437.html",
          "name" : "20060116 MPM HP-180W VoIP wireless desktop phone undocumented port UDP/9090",
          "refsource" : "FULLDISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18512",
          "name" : "18512",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16285",
          "name" : "16285",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24147",
          "name" : "mpn-hp180w-default-port(24147)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "MPM SIP HP-180W Wireless IP Phone WE.00.17 allows remote attackers to obtain sensitive information and possibly cause a denial of service via a direct connection to UDP port 9090, which is undocumented and does not require authentication."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:mpm:hp-180w_voip_wifi_phone:we.00.17:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.4
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-22T20:03Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0361",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "bit_5_blog",
            "product" : {
              "product_data" : [ {
                "product_name" : "bit_5_blog",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.01",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://evuln.com/vulns/32/exploit",
          "name" : "http://evuln.com/vulns/32/exploit",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://evuln.com/vulns/32/summary/",
          "name" : "http://evuln.com/vulns/32/summary/",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18464",
          "name" : "18464",
          "refsource" : "SECUNIA",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/22446",
          "name" : "22446",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/421994/100/0/threaded",
          "name" : "20060115 [eVuln] Bit 5 Blog JavaScript Insertion Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16246",
          "name" : "16246",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0195",
          "name" : "ADV-2006-0195",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24129",
          "name" : "bit5blog-addcomment-xss(24129)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in addcomment.php in Bit 5 Blog 8.01 allows remote attackers to inject arbitrary web script or HTML via a javascript URI in an <a> tag in the comment parameter, which strips most tags but not <a>."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bit_5_blog:bit_5_blog:8.01:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-22T20:03Z",
    "lastModifiedDate" : "2018-10-19T15:44Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0362",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "3com",
            "product" : {
              "product_data" : [ {
                "product_name" : "tippingpoint_ips_tos",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.1.3.6323",
                    "version_affected" : "<="
                  }, {
                    "version_value" : "2.2.0.6504",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-399"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://isc.sans.org/diary.php?storyid=1042",
          "name" : "http://isc.sans.org/diary.php?storyid=1042",
          "refsource" : "MISC",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://secunia.com/advisories/18515",
          "name" : "18515",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1015511",
          "name" : "1015511",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.eweek.com/article2/0,1759,1912048,00.asp",
          "name" : "http://www.eweek.com/article2/0,1759,1912048,00.asp",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.osvdb.org/22504",
          "name" : "22504",
          "refsource" : "OSVDB",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16299",
          "name" : "16299",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24200",
          "name" : "tippingpoint-ips-http-traffic-dos(24200)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "TippingPoint Intrusion Prevention System (IPS) TOS before 2.1.4.6324, and TOS 2.2.x before 2.2.1.6506, allow remote attackers to cause a denial of service (CPU consumption) via an unknown vector, probably involving an HTTP request with a negative number in the Content-Length header."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:3com:tippingpoint_ips_tos:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "2.1.3.6323"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:3com:tippingpoint_ips_tos:2.2.0.6504:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-22T20:03Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0363",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "msn_messenger",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.5",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.msn-password-recovery.com/",
          "name" : "http://www.msn-password-recovery.com/",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/421921/100/0/threaded",
          "name" : "20060113 Re: MSN Messenger Password Decrypter for WinXP/2003",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/422283/100/0/threaded",
          "name" : "20060117 Re: MSN Messenger Password Decrypter for WinXP/2003",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The \"Remember my Password\" feature in MSN Messenger 7.5 stores passwords in an encrypted format under the HKEY_CURRENT_USER\\Software\\Microsoft\\IdentityCRL\\Creds registry key, which might allow local users to obtain the original passwords via a program that calls CryptUnprotectData, as demonstrated by the \"MSN Password Recovery.exe\" program.  NOTE: it could be argued that local-only password recovery is inherently insecure because the decryption methods and keys must be stored somewhere on the local system, and are thus inherently accessible with varying degrees of effort.  Perhaps this issue should not be included in CVE."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:msn_messenger:7.5:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 2.1
        },
        "severity" : "LOW",
        "exploitabilityScore" : 3.9,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-22T20:03Z",
    "lastModifiedDate" : "2018-10-19T15:44Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0364",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "mybulletinboard",
            "product" : {
              "product_data" : [ {
                "product_name" : "mybulletinboard",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0_final",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0_pr2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0_preview_release_2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0_rc2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0_rc4",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://archives.neohapsis.com/archives/bugtraq/2006-01/0332.html",
          "name" : "20060118 MyBB Signature HTML Code Injection",
          "refsource" : "BUGTRAQ",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://secunia.com/advisories/18544",
          "name" : "18544",
          "refsource" : "SECUNIA",
          "tags" : [ "Exploit", "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/22628",
          "name" : "22628",
          "refsource" : "OSVDB",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16308",
          "name" : "16308",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0255",
          "name" : "ADV-2006-0255",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24225",
          "name" : "mybb-html-signature-xss(24225)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in MyBulletinBoard (MyBB) allows remote attackers to inject arbitrary web script or HTML via a signature containing a JavaScript URI in the SRC attribute of an IMG element, in which the URI uses SGML numeric character references without trailing semicolons, as demonstrated by \"&#106&#97&#118&#97&#115&#99&#114&#105&#112&#116\"."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mybulletinboard:mybulletinboard:1.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mybulletinboard:mybulletinboard:1.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mybulletinboard:mybulletinboard:1.0_final:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mybulletinboard:mybulletinboard:1.0_pr2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mybulletinboard:mybulletinboard:1.0_preview_release_2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mybulletinboard:mybulletinboard:1.0_rc2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mybulletinboard:mybulletinboard:1.0_rc4:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2006-01-22T20:03Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0365",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "xmb_software",
            "product" : {
              "product_data" : [ {
                "product_name" : "xmb_forum",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.osvdb.org/27920",
          "name" : "27920",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/422277/100/0/threaded",
          "name" : "20060118 XMB Forum HTML Code Injection",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24208",
          "name" : "xmbforum-imgsrc-xss(24208)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in XMB (aka extreme message board) allows remote attackers to inject arbitrary web script or HTML via JavaScript in the SRC attribute of an IMG element."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:xmb_software:xmb_forum:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-22T20:03Z",
    "lastModifiedDate" : "2018-10-19T15:44Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0366",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "phpclanwebsite",
            "product" : {
              "product_data" : [ {
                "product_name" : "phpclanwebsite",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.23.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18541",
          "name" : "18541",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/422265/100/0/threaded",
          "name" : "20060117 Phpclanwebsite BBCode IMG Tag XSS Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16300",
          "name" : "16300",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0254",
          "name" : "ADV-2006-0254",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://archive.cert.uni-stuttgart.de/bugtraq/2006/01/msg00343.html",
          "name" : "20060118 Phpclanwebsite BBCode IMG Tag XSS Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in Phpclanwebsite (aka PCW) allows remote attackers to inject arbitrary web script or HTML via a javascript URI in a BBCode img tag."
        }, {
          "lang" : "en",
          "value" : "A simple fix has been released on the Main PCW site available directly at <a href=\"http://www.phpclanwebsite.com/index.php?page=downloads&func=browselist&par=1\">http://www.phpclanwebsite.com/index.php?page=downloads&func=browselist&par=1\r\n</a>Please download and install imediately."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:phpclanwebsite:phpclanwebsite:1.23.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-22T20:03Z",
    "lastModifiedDate" : "2018-10-19T15:44Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0367",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "cisco",
            "product" : {
              "product_data" : [ {
                "product_name" : "call_manager",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.1(2)",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.1(3a)",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.3(3)",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.3(3)es61",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.3(4)es25",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.3(5)",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0(2a)es40",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0(2a)sr2b",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1(2)es33",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1(3)es07",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1(3)sr1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18501",
          "name" : "18501",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1015502",
          "name" : "1015502",
          "refsource" : "SECTRACK",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.cisco.com/warp/public/707/cisco-sa-20060118-ccmpe.shtml",
          "name" : "20060118 Cisco Call Manager Privilege Escalation",
          "refsource" : "CISCO",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/22621",
          "name" : "22621",
          "refsource" : "OSVDB",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16293",
          "name" : "16293",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0250",
          "name" : "ADV-2006-0250",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24172",
          "name" : "cisco-callmanager-ccmadmin-gain-priv(24172)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in Cisco CallManager 3.2 and earlier, 3.3 before 3.3(5)SR1, 4.0 before 4.0(2a)SR2c, and 4.1 before 4.1(3)SR2 allows remote authenticated users with read-only administrative privileges to obtain full administrative privileges via a \"crafted URL on the CCMAdmin web page.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:call_manager:1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:call_manager:2.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:call_manager:3.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:call_manager:3.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:call_manager:3.1\\(2\\):*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:call_manager:3.1\\(3a\\):*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:call_manager:3.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:call_manager:3.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:call_manager:3.3\\(3\\):*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:call_manager:3.3\\(3\\)es61:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:call_manager:3.3\\(4\\)es25:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:call_manager:3.3\\(5\\):*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:call_manager:4.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:call_manager:4.0\\(2a\\)es40:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:call_manager:4.0\\(2a\\)sr2b:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:call_manager:4.1\\(2\\)es33:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:call_manager:4.1\\(3\\)es07:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:call_manager:4.1\\(3\\)sr1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.5
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-22T20:03Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0368",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "cisco",
            "product" : {
              "product_data" : [ {
                "product_name" : "call_manager",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.1(2)",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.1(3a)",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.3(3)",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.3(3)es61",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.3(4)es25",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.3(5)",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.3(5)es30",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0(2a)es40",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0(2a)es62",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0(2a)sr2b",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1(2)es33",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1(2)es55",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1(3)es07",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1(3)es32",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1(3)sr1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18494",
          "name" : "18494",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/359",
          "name" : "359",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1015503",
          "name" : "1015503",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.cisco.com/warp/public/707/cisco-sa-20060118-ccmdos.shtml",
          "name" : "20060118 Cisco Call Manager Denial of Service",
          "refsource" : "CISCO",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/22622",
          "name" : "22622",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/22623",
          "name" : "22623",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16295",
          "name" : "16295",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0249",
          "name" : "ADV-2006-0249",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24180",
          "name" : "cisco-callmanager-port-connection-dos(24180)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cisco CallManager 3.2 and earlier, 3.3 before 3.3(5)SR1, 4.0 before 4.0(2a)SR2c, and 4.1 before 4.1(3)SR2 allow remote attackers to (1) cause a denial of service (CPU and memory consumption) via a large number of open TCP connections to port 2000 and (2) cause a denial of service (fill the Windows Service Manager communication queue) via a large number of TCP connections to port 2001, 2002, or 7727."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:call_manager:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:call_manager:1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:call_manager:2.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:call_manager:3.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:call_manager:3.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:call_manager:3.1\\(2\\):*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:call_manager:3.1\\(3a\\):*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:call_manager:3.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:call_manager:3.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:call_manager:3.3\\(3\\):*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:call_manager:3.3\\(3\\)es61:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:call_manager:3.3\\(4\\)es25:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:call_manager:3.3\\(5\\):*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:call_manager:3.3\\(5\\)es30:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:call_manager:4.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:call_manager:4.0\\(2a\\)es40:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:call_manager:4.0\\(2a\\)es62:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:call_manager:4.0\\(2a\\)sr2b:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:call_manager:4.1\\(2\\)es33:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:call_manager:4.1\\(2\\)es55:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:call_manager:4.1\\(3\\)es07:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:call_manager:4.1\\(3\\)es32:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:call_manager:4.1\\(3\\)sr1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.8
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-22T20:03Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0369",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "mysql",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.0.18",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-200"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/archive/1/422491/100/0/threaded",
          "name" : "20060120 MySQL 5.0 information leak?",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/422592/100/0/threaded",
          "name" : "20060121 RE: MySQL 5.0 information leak?",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/422698/100/0/threaded",
          "name" : "20060121 Re: MySQL 5.0 information leak?",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/423180/30/7310/threaded",
          "name" : "20060122 Re: MySQL 5.0 information leak?",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/423204/100/0/threaded",
          "name" : "20060124 Re: MySQL 5.0 information leak?",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/423228/100/0/threaded",
          "name" : "20060123 RE: MySQL 5.0 information leak?",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/423432/100/0/threaded",
          "name" : "20060128 Re: MySQL 5.0 information leak?",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "** DISPUTED **  MySQL 5.0.18 allows local users with access to a VIEW to obtain sensitive information via the \"SELECT * FROM information_schema.views;\" query, which returns the query that created the VIEW.  NOTE: this issue has been disputed by third parties, saying that the availability of the schema is a normal and sometimes desired aspect of database access."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:5.0.18:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 2.1
        },
        "severity" : "LOW",
        "exploitabilityScore" : 3.9,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-22T20:03Z",
    "lastModifiedDate" : "2019-12-17T17:13Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0370",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "noah_medling",
            "product" : {
              "product_data" : [ {
                "product_name" : "rcblog",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.03",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://evuln.com/vulns/42/summary.html",
          "name" : "http://evuln.com/vulns/42/summary.html",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18547",
          "name" : "18547",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1015523",
          "name" : "1015523",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.fluffington.com/index.php?page=rcblog",
          "name" : "http://www.fluffington.com/index.php?page=rcblog",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/22679",
          "name" : "22679",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/422499/100/0/threaded",
          "name" : "20060120 [eVuln] RCBlog Directory Traversal & Sensitive Information Disclosure",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24249",
          "name" : "rcblog-data-config-insecure-directories(24249)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Noah Medling RCBlog 1.03 stores the data and config directories under the web root with insufficient access control, which allows remote attackers to view account names and MD5 password hashes."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:noah_medling:rcblog:1.03:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-22T20:03Z",
    "lastModifiedDate" : "2018-10-19T15:44Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0371",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "noah_medling",
            "product" : {
              "product_data" : [ {
                "product_name" : "rcblog",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.03",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://evuln.com/vulns/42/summary.html",
          "name" : "http://evuln.com/vulns/42/summary.html",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18547",
          "name" : "18547",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1015523",
          "name" : "1015523",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.fluffington.com/index.php?page=rcblog",
          "name" : "http://www.fluffington.com/index.php?page=rcblog",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/22680",
          "name" : "22680",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/422499/100/0/threaded",
          "name" : "20060120 [eVuln] RCBlog Directory Traversal & Sensitive Information Disclosure",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/425392/100/0/threaded",
          "name" : "20060218 RCblog exploit [fun]",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/436784/30/4500/threaded",
          "name" : "20060611 RCblog 1.03 Directory Traversal [index.php]",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16342",
          "name" : "16342",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24248",
          "name" : "rcblog-index-directory-traversal(24248)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/27042",
          "name" : "rcblog-index-file-include(27042)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Directory traversal vulnerability in index.php in Noah Medling RCBlog 1.03 allows remote attackers to read arbitrary .txt files, possibly including one that stores the administrator's account name and password, via a .. (dot dot) in the post parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:noah_medling:rcblog:1.03:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-22T20:03Z",
    "lastModifiedDate" : "2018-10-19T15:44Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0372",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "insane_visions",
            "product" : {
              "product_data" : [ {
                "product_name" : "blogphp",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://securityreason.com/securityalert/365",
          "name" : "365",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/22738",
          "name" : "22738",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/422483/100/0/threaded",
          "name" : "20060120 BlogPHP config.php SQL injection login bypass",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/422484/100/0/threaded",
          "name" : "20060120 BlogPHP config.php SQL injection login bypass",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/422593/100/0/threaded",
          "name" : "20060121 BlogPHP config.php SQL injection login bypassed",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16340",
          "name" : "16340",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24131",
          "name" : "blogphp-index-bypass-security(24131)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple SQL injection vulnerabilities in config.php in Insane Visions BlogPHP, possibly 1.0, allow remote attackers to execute arbitrary SQL commands via the (1) blogphp_username or (2) blogphp_password parameter in a cookie."
        }, {
          "lang" : "en",
          "value" : "BlogPHP version 2.0 was released to fix the config.php exploit and is available for download at <a href=\"http://sourceforge.net/project/showfiles.php?group_id=156043\">http://sourceforge.net/project/showfiles.php?group_id=156043</a>."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:insane_visions:blogphp:1.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-22T20:03Z",
    "lastModifiedDate" : "2018-10-19T15:44Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0373",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "douran",
            "product" : {
              "product_data" : [ {
                "product_name" : "followweb",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.osvdb.org/27918",
          "name" : "27918",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16302",
          "name" : "16302",
          "refsource" : "BID",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in register.aspx in Douran FollowWeb allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:douran:followweb:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-22T20:03Z",
    "lastModifiedDate" : "2008-09-05T20:59Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0374",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "advantage_century_telecommunication",
            "product" : {
              "product_data" : [ {
                "product_name" : "p202s",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.01.21_firmware_1.1.21",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-287"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.grok.org.uk/pipermail/full-disclosure/2006-January/041434.html",
          "name" : "20060116 ACT P202S VoIP wireless phone multiple undocumented ports/services",
          "refsource" : "FULLDISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18514",
          "name" : "18514",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16288",
          "name" : "16288",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24149",
          "name" : "act-p202s-default-port(24149)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Advantage Century Telecommunication (ACT) P202S IP Phone 1.01.21 running firmware 1.1.21 has multiple undocumented ports available, which (1) might allow remote attackers to obtain sensitive information, such as memory contents and internal operating-system data, by directly accessing the VxWorks WDB remote debugging ONCRPC (aka wdbrpc) on UDP 17185, (2) reflect network data using echo (TCP 7), or (3) gain access without authentication using rlogin (TCP 513)."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:advantage_century_telecommunication:p202s:1.01.21_firmware_1.1.21:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-22T20:03Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0375",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "advantage_century_telecommunication",
            "product" : {
              "product_data" : [ {
                "product_name" : "p202s",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.01.21_firmware_1.1.21",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.grok.org.uk/pipermail/full-disclosure/2006-January/041434.html",
          "name" : "20060116 ACT P202S VoIP wireless phone multiple undocumented ports/services",
          "refsource" : "FULLDISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18514",
          "name" : "18514",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16288",
          "name" : "16288",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24149",
          "name" : "act-p202s-default-port(24149)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Advantage Century Telecommunication (ACT) P202S IP Phone 1.01.21 running firmware 1.1.21 on VxWorks uses a hardcoded Network Time Protocol (NTP) server in Taiwan, which could allow remote attackers to provide false time information, block access to time information, or conduct other attacks."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:advantage_century_telecommunication:p202s:1.01.21_firmware_1.1.21:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-22T20:03Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0376",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "windows_2000",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_2003_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "r2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_xp",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://securityreason.com/securityalert/349",
          "name" : "349",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1015489",
          "name" : "1015489",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.nmrc.org/pub/advise/20060114.txt",
          "name" : "http://www.nmrc.org/pub/advise/20060114.txt",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securiteam.com/windowsntfocus/5YP0D2KHHO.html",
          "name" : "http://www.securiteam.com/windowsntfocus/5YP0D2KHHO.html",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/421868/100/0/threaded",
          "name" : "20060114 [NMRC Advisory] Microsoft Windows Wireless Exposure on Laptops",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.theta44.org/karma/",
          "name" : "http://www.theta44.org/karma/",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24157",
          "name" : "windows-wireless-adhoc-unauth-access(24157)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The 802.11 wireless client in certain operating systems including Windows 2000, Windows XP, and Windows Server 2003 does not warn the user when (1) it establishes an association with a station in ad hoc (aka peer-to-peer) mode or (2) a station in ad hoc mode establishes an association with it, which allows remote attackers to put unexpected wireless communication into place."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2000:*:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2000:*:sp3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2000:*:sp4:*:fr:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:r2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_xp:*:gold:home:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_xp:*:gold:professional:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-22T20:03Z",
    "lastModifiedDate" : "2018-10-19T15:44Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0377",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "squirrelmail",
            "product" : {
              "product_data" : [ {
                "product_name" : "squirrelmail",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.3_r3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.3_rc1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.3a",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.4_rc1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.6_rc1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4_rc1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "ftp://patches.sgi.com/support/free/security/advisories/20060501-01-U.asc",
          "name" : "20060501-01-U",
          "refsource" : "SGI",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18985",
          "name" : "18985",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/19130",
          "name" : "19130",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/19131",
          "name" : "19131",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/19176",
          "name" : "19176",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/19205",
          "name" : "19205",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/19960",
          "name" : "19960",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/20210",
          "name" : "20210",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1015662",
          "name" : "1015662",
          "refsource" : "SECTRACK",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.debian.org/security/2006/dsa-988",
          "name" : "DSA-988",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.gentoo.org/security/en/glsa/glsa-200603-09.xml",
          "name" : "GLSA-200603-09",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDKSA-2006:049",
          "name" : "MDKSA-2006:049",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.novell.com/linux/security/advisories/2006_05_sr.html",
          "name" : "SUSE-SR:2006:005",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/archives/fedora-announce-list/2006-March/msg00004.html",
          "name" : "FEDORA-2006-133",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2006-0283.html",
          "name" : "RHSA-2006:0283",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16756",
          "name" : "16756",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.squirrelmail.org/security/issue/2006-02-15",
          "name" : "http://www.squirrelmail.org/security/issue/2006-02-15",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0689",
          "name" : "ADV-2006-0689",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24849",
          "name" : "squirrelmail-mailbox-imap-injection(24849)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11470",
          "name" : "oval:org.mitre.oval:def:11470",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "CRLF injection vulnerability in SquirrelMail 1.4.0 to 1.4.5 allows remote attackers to inject arbitrary IMAP commands via newline characters in the mailbox parameter of the sqimap_mailbox_select command, aka \"IMAP injection.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:squirrelmail:squirrelmail:1.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:squirrelmail:squirrelmail:1.4.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:squirrelmail:squirrelmail:1.4.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:squirrelmail:squirrelmail:1.4.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:squirrelmail:squirrelmail:1.4.3_r3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:squirrelmail:squirrelmail:1.4.3_rc1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:squirrelmail:squirrelmail:1.4.3a:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:squirrelmail:squirrelmail:1.4.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:squirrelmail:squirrelmail:1.4.4_rc1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:squirrelmail:squirrelmail:1.4.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:squirrelmail:squirrelmail:1.4.6_rc1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:squirrelmail:squirrelmail:1.4_rc1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-24T00:02Z",
    "lastModifiedDate" : "2017-10-11T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0378",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "netrix",
            "product" : {
              "product_data" : [ {
                "product_name" : "x-site_manager",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/ref/22/22634-x-site.txt",
          "name" : "http://osvdb.org/ref/22/22634-x-site.txt",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://secunia.com/advisories/18537",
          "name" : "18537",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/22634",
          "name" : "22634",
          "refsource" : "OSVDB",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16313",
          "name" : "16313",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0253",
          "name" : "ADV-2006-0253",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24234",
          "name" : "xsitemanager-productdetails-xss(24234)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in Netrix X-Site Manager allows remote attackers to inject arbitrary web script or HTML via the product_id parameter, as originally demonstrated for a custom mp3players_details.php program.  NOTE: the name of the affected program might be installation-dependent, but it has been identified as \"product_details.php\" by some sources."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:netrix:x-site_manager:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-23T20:03Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0379",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "freebsd",
            "product" : {
              "product_data" : [ {
                "product_name" : "freebsd",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-06:06.kmem.asc",
          "name" : "FreeBSD-SA-06:06",
          "refsource" : "FREEBSD",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18599",
          "name" : "18599",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1015541",
          "name" : "1015541",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/22730",
          "name" : "22730",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16373",
          "name" : "16373",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24338",
          "name" : "bsd-buffer-initialization-disclosure(24338)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "FreeBSD kernel 5.4-STABLE and 6.0 does not completely initialize a buffer before making it available to userland, which could allow local users to read portions of kernel memory."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:freebsd:freebsd:5.4:stable:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:freebsd:freebsd:6.0:stable:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 2.1
        },
        "severity" : "LOW",
        "exploitabilityScore" : 3.9,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-25T22:03Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0380",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "freebsd",
            "product" : {
              "product_data" : [ {
                "product_name" : "freebsd",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-06:06.kmem.asc",
          "name" : "FreeBSD-SA-06:06",
          "refsource" : "FREEBSD",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18599",
          "name" : "18599",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1015541",
          "name" : "1015541",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/22731",
          "name" : "22731",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16373",
          "name" : "16373",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24340",
          "name" : "bsd-buffer-length-disclosure(24340)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "A logic error in FreeBSD kernel 5.4-STABLE and 6.0 causes the kernel to calculate an incorrect buffer length, which causes more data to be copied to userland than intended, which could allow local users to read portions of kernel memory."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:freebsd:freebsd:5.4:stable:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:freebsd:freebsd:6.0:stable:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 2.1
        },
        "severity" : "LOW",
        "exploitabilityScore" : 3.9,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-25T22:03Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0381",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "freebsd",
            "product" : {
              "product_data" : [ {
                "product_name" : "freebsd",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-06:07.pf.asc",
          "name" : "FreeBSD-SA-06:07",
          "refsource" : "FREEBSD",
          "tags" : [ "Patch" ]
        }, {
          "url" : "ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2006-004.txt.asc",
          "name" : "NetBSD-SA2006-004",
          "refsource" : "NETBSD",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18609",
          "name" : "18609",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1015542",
          "name" : "1015542",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.openbsd.org/cgi-bin/cvsweb/src/sys/net/pf_norm.c.diff?r1=1.103&r2=1.104",
          "name" : "http://www.openbsd.org/cgi-bin/cvsweb/src/sys/net/pf_norm.c.diff?r1=1.103&r2=1.104",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/22732",
          "name" : "22732",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16375",
          "name" : "16375",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24337",
          "name" : "bsd-pf-fragment-dos(24337)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "A logic error in the IP fragment cache functionality in pf in FreeBSD 5.3, 5.4, and 6.0, and OpenBSD, when a 'scrub fragment crop' or 'scrub fragment drop-ovl' rule is being used, allows remote attackers to cause a denial of service (crash) via crafted packets that cause a packet fragment to be inserted twice."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:freebsd:freebsd:5.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:freebsd:freebsd:5.3:release:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:freebsd:freebsd:5.3:releng:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:freebsd:freebsd:5.3:stable:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:freebsd:freebsd:5.4:pre-release:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:freebsd:freebsd:5.4:release:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:freebsd:freebsd:5.4:releng:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:freebsd:freebsd:6.0:release:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:freebsd:freebsd:6.0:stable:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-25T22:03Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0382",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apple",
            "product" : {
              "product_data" : [ {
                "product_name" : "mac_os_x",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.4.5",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.apple.com/archives/security-announce/2006/Feb/msg00000.html",
          "name" : "APPLE-SA-2006-02-14",
          "refsource" : "APPLE",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18907",
          "name" : "18907",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1015634",
          "name" : "1015634",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/23190",
          "name" : "23190",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16654",
          "name" : "16654",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0597",
          "name" : "ADV-2006-0597",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24682",
          "name" : "macosx-system-call-dos(24682)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Apple Mac OS X 10.4.5 and allows local users to cause a denial of service (crash) via an undocumented system call."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.5:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 2.1
        },
        "severity" : "LOW",
        "exploitabilityScore" : 3.9,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-14T22:06Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0383",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apple",
            "product" : {
              "product_data" : [ {
                "product_name" : "mac_os_x",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.3.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.3.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.3.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.3.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.3.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.3.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.3.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.3.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.3.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.5",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "mac_os_x_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.3.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.3.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.3.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.3.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.3.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.3.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.3.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.3.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.3.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.5",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://docs.info.apple.com/article.html?artnum=303382",
          "name" : "http://docs.info.apple.com/article.html?artnum=303382",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://lists.apple.com/archives/security-announce/2006/Mar/msg00000.html",
          "name" : "APPLE-SA-2006-03-01",
          "refsource" : "APPLE",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/19064",
          "name" : "19064",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/23643",
          "name" : "23643",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16907",
          "name" : "16907",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA06-062A.html",
          "name" : "TA06-062A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0791",
          "name" : "ADV-2006-0791",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/25025",
          "name" : "macosx-vpn-dos(25025)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "IPSec when used with VPN networks in Mac OS X 10.4 through 10.4.5 allows remote attackers to cause a denial of service (application crash) via unspecified vectors involving the \"incorrect handling of error conditions\"."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.3.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.3.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.3.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.3.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.3.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.3.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.3.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.3.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.3.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.3.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.3.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.3.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.3.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.3.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.3.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.3.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.3.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.3.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.5:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-03-02T19:06Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0384",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apple",
            "product" : {
              "product_data" : [ {
                "product_name" : "mac_os_x",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.3.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.3.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.3.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.3.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.3.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.3.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.3.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.3.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.3.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.5",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "mac_os_x_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.3.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.3.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.3.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.3.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.3.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.3.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.3.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.3.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.3.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.5",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://docs.info.apple.com/article.html?artnum=303382",
          "name" : "http://docs.info.apple.com/article.html?artnum=303382",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://lists.apple.com/archives/security-announce/2006/Mar/msg00000.html",
          "name" : "APPLE-SA-2006-03-01",
          "refsource" : "APPLE",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/19064",
          "name" : "19064",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1015709",
          "name" : "1015709",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/23640",
          "name" : "23640",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16907",
          "name" : "16907",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA06-062A.html",
          "name" : "TA06-062A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0791",
          "name" : "ADV-2006-0791",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/25021",
          "name" : "macosx-automount-execute-code(25021)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "automount in Mac OS X 10.4.5 and earlier allows remote file servers to cause a denial of service (unresponsiveness) or execute arbitrary code via unspecified vectors that cause automount to \"mount file systems with reserved names\"."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.3.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.3.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.3.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.3.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.3.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.3.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.3.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.3.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.3.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.3.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.3.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.3.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.3.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.3.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.3.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.3.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.3.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.3.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.5:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-03-02T19:06Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0386",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apple",
            "product" : {
              "product_data" : [ {
                "product_name" : "mac_os_x",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.3.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.3.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.3.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.3.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.3.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.3.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.3.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.3.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.3.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.5",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "mac_os_x_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.3.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.3.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.3.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.3.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.3.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.3.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.3.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.3.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.3.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.5",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://docs.info.apple.com/article.html?artnum=303382",
          "name" : "http://docs.info.apple.com/article.html?artnum=303382",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://lists.apple.com/archives/security-announce/2006/Mar/msg00000.html",
          "name" : "APPLE-SA-2006-03-01",
          "refsource" : "APPLE",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/19064",
          "name" : "19064",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/23642",
          "name" : "23642",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16907",
          "name" : "16907",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA06-062A.html",
          "name" : "TA06-062A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0791",
          "name" : "ADV-2006-0791",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/25024",
          "name" : "macosx-filevault-file-access(25024)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "FileVault in Mac OS X 10.4.5 and earlier does not properly mount user directories when creating a FileVault image, which allows local users to access protected files when FileVault is enabled."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.3.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.3.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.3.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.3.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.3.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.3.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.3.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.3.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.3.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.3.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.3.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.3.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.3.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.3.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.3.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.3.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.3.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.3.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.5:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:S/C:P/I:N/A:N",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 1.7
        },
        "severity" : "LOW",
        "exploitabilityScore" : 3.1,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-03-03T22:02Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0387",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apple",
            "product" : {
              "product_data" : [ {
                "product_name" : "mac_os_x",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.3.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.3.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.3.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.3.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.3.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.3.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.3.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.3.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.3.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.5",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "mac_os_x_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.3.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.3.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.3.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.3.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.3.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.3.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.3.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.3.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.3.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.5",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://docs.info.apple.com/article.html?artnum=303382",
          "name" : "http://docs.info.apple.com/article.html?artnum=303382",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://lists.apple.com/archives/security-announce/2006/Mar/msg00000.html",
          "name" : "APPLE-SA-2006-03-01",
          "refsource" : "APPLE",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/19064",
          "name" : "19064",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1015713",
          "name" : "1015713",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/176732",
          "name" : "VU#176732",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16907",
          "name" : "16907",
          "refsource" : "BID",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA06-062A.html",
          "name" : "TA06-062A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0791",
          "name" : "ADV-2006-0791",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/25032",
          "name" : "macosx-safari-bo(25032)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Stack-based buffer overflow in Safari in Mac OS X 10.4.5 and earlier, and 10.3.9 and earlier, allows remote attackers to execute arbitrary code via unspecified vectors involving a web page with crafted JavaScript, a different vulnerability than CVE-2005-4504."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.3.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.3.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.3.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.3.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.3.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.3.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.3.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.3.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.3.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.3.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.3.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.3.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.3.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.3.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.3.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.3.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.3.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.3.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.5:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.4
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-03-06T20:06Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0388",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apple",
            "product" : {
              "product_data" : [ {
                "product_name" : "mac_os_x",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.3.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.3.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.3.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.3.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.3.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.3.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.3.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.3.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.3.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.5",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "mac_os_x_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.3.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.3.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.3.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.3.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.3.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.3.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.3.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.3.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.3.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.5",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-94"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://docs.info.apple.com/article.html?artnum=303382",
          "name" : "http://docs.info.apple.com/article.html?artnum=303382",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://lists.apple.com/archives/security-announce/2006/Mar/msg00000.html",
          "name" : "APPLE-SA-2006-03-01",
          "refsource" : "APPLE",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://secunia.com/advisories/19064",
          "name" : "19064",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1015713",
          "name" : "1015713",
          "refsource" : "SECTRACK",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16907",
          "name" : "16907",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA06-062A.html",
          "name" : "TA06-062A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0791",
          "name" : "ADV-2006-0791",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/25038",
          "name" : "macosx-safari-http-redirect(25038)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Safari in Mac OS X 10.3 before 10.3.9 and 10.4 before 10.4.5 allows remote attackers to redirect users to local files and execute arbitrary JavaScript via unspecified vectors involving HTTP redirection to local resources."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.3.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.3.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.3.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.3.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.3.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.3.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.3.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.3.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.3.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.3.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.3.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.3.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.3.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.3.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.3.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.3.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.3.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.3.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.5:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:H/Au:N/C:N/I:P/A:P",
          "accessVector" : "LOCAL",
          "accessComplexity" : "HIGH",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 2.6
        },
        "severity" : "LOW",
        "exploitabilityScore" : 1.9,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2006-03-03T22:02Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0389",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apple",
            "product" : {
              "product_data" : [ {
                "product_name" : "mac_os_x",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.5",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "mac_os_x_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.5",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://docs.info.apple.com/article.html?artnum=303382",
          "name" : "http://docs.info.apple.com/article.html?artnum=303382",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://lists.apple.com/archives/security-announce/2006/Mar/msg00000.html",
          "name" : "APPLE-SA-2006-03-01",
          "refsource" : "APPLE",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/19064",
          "name" : "19064",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/23649",
          "name" : "23649",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16907",
          "name" : "16907",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA06-062A.html",
          "name" : "TA06-062A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0791",
          "name" : "ADV-2006-0791",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/25040",
          "name" : "macosx-syndication-xss(25040)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in Syndication (Safari RSS) in Mac OS X 10.4 through 10.4.5 allows remote attackers to execute arbitrary JavaScript via unspecified vectors involving RSS feeds."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.5:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:H/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "HIGH",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 2.6
        },
        "severity" : "LOW",
        "exploitabilityScore" : 4.9,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2006-03-03T22:02Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0390",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ ]
        } ]
      },
      "references" : {
        "reference_data" : [ ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2005-4504.  Reason: This candidate is a duplicate of CVE-2005-4504.  Notes: All CVE users should reference CVE-2005-4504 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ ]
    },
    "impact" : { },
    "publishedDate" : "2006-03-06T20:06Z",
    "lastModifiedDate" : "2008-09-10T19:58Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0391",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apple",
            "product" : {
              "product_data" : [ {
                "product_name" : "mac_os_x",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.3.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.3.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.3.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.3.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.3.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.3.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.3.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.4",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://docs.info.apple.com/article.html?artnum=303382",
          "name" : "http://docs.info.apple.com/article.html?artnum=303382",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://lists.apple.com/archives/security-announce/2006/Mar/msg00000.html",
          "name" : "APPLE-SA-2006-03-01",
          "refsource" : "APPLE",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/19064",
          "name" : "19064",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.idefense.com/intelligence/vulnerabilities/display.php?id=399",
          "name" : "20060302 Apple MacOS X BOMArchiveHelper Directory Traversal Vulnerability",
          "refsource" : "IDEFENSE",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/23641",
          "name" : "23641",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16907",
          "name" : "16907",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA06-062A.html",
          "name" : "TA06-062A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0791",
          "name" : "ADV-2006-0791",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/25023",
          "name" : "macosx-bom-directory-traversal(25023)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Directory traversal vulnerability in the BOM framework in Mac OS X 10.x before 10.3.9 and 10.4 before 10.4.5 allows user-assisted attackers to overwrite or create arbitrary files via an archive that is handled by BOMArchiveHelper."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.3.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.3.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.3.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.3.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.3.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.3.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.3.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.4:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:S/C:N/I:P/A:N",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 1.7
        },
        "severity" : "LOW",
        "exploitabilityScore" : 3.1,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-03-03T22:02Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0392",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apple",
            "product" : {
              "product_data" : [ {
                "product_name" : "mac_os_x",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.4.7",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "mac_os_x_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.4.7",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.apple.com/archives/security-announce/2006//Aug/msg00000.html",
          "name" : "APPLE-SA-2006-08-01",
          "refsource" : "APPLE",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/21253",
          "name" : "21253",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/527236",
          "name" : "VU#527236",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.osvdb.org/27739",
          "name" : "27739",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/19289",
          "name" : "19289",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA06-214A.html",
          "name" : "TA06-214A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/3101",
          "name" : "ADV-2006-3101",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/28142",
          "name" : "macosx-raw-image-bo(28142)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Buffer overflow in Apple Mac OS X 10.4.7 allows user-assisted attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted Canon RAW image."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.7:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:H/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "HIGH",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.1
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 4.9,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2006-08-03T01:04Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0393",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apple",
            "product" : {
              "product_data" : [ {
                "product_name" : "mac_os_x",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.4.7",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "mac_os_x_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.4.7",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.apple.com/archives/security-announce/2006//Aug/msg00000.html",
          "name" : "APPLE-SA-2006-08-01",
          "refsource" : "APPLE",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/21253",
          "name" : "21253",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1016672",
          "name" : "1016672",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/27745",
          "name" : "27745",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/19289",
          "name" : "19289",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA06-214A.html",
          "name" : "TA06-214A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/3101",
          "name" : "ADV-2006-3101",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/28147",
          "name" : "macosx-openssh-nonexistent-user-dos(28147)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "OpenSSH in Apple Mac OS X 10.4.7 allows remote attackers to cause a denial of service or determine account existence by attempting to log in using an invalid user, which causes the server to hang."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.7:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:H/Au:N/C:P/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "HIGH",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 4.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 4.9,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-08-03T01:04Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0394",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ ]
        } ]
      },
      "references" : {
        "reference_data" : [ ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2006-0848.  Reason: This candidate is a duplicate of CVE-2006-0848.  Notes: All CVE users should reference CVE-2006-0848 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ ]
    },
    "impact" : { },
    "publishedDate" : "2006-03-02T01:02Z",
    "lastModifiedDate" : "2008-09-10T19:58Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0395",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apple",
            "product" : {
              "product_data" : [ {
                "product_name" : "mac_os_x",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.4.5",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "mac_os_x_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.4.5",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://docs.info.apple.com/article.html?artnum=303382",
          "name" : "http://docs.info.apple.com/article.html?artnum=303382",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://lists.apple.com/archives/client-management/2006/Mar/msg00030.html",
          "name" : "APPLE-SA-2006-03-01",
          "refsource" : "APPLE",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/19064",
          "name" : "19064",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/23645",
          "name" : "23645",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16907",
          "name" : "16907",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA06-062A.html",
          "name" : "TA06-062A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0791",
          "name" : "ADV-2006-0791",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/25027",
          "name" : "macosx-mail-bypass-security(25027)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The Download Validation in Mail in Mac OS X 10.4 does not properly recognize attachment file types to warn a user of an unsafe type, which allows user-assisted remote attackers to execute arbitrary code via crafted file types."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.5:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:H/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "HIGH",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.1
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 4.9,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2006-08-05T01:04Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0396",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apple",
            "product" : {
              "product_data" : [ {
                "product_name" : "mac_os_x",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.5",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "mac_os_x_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.5",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://docs.info.apple.com/article.html?artnum=303453",
          "name" : "http://docs.info.apple.com/article.html?artnum=303453",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://lists.apple.com/archives/security-announce/2006/Mar/msg00001.html",
          "name" : "APPLE-SA-2006-03-13",
          "refsource" : "APPLE",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/19129",
          "name" : "19129",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1015762",
          "name" : "1015762",
          "refsource" : "SECTRACK",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.digitalmunition.com/DMA%5B2006-0313a%5D.txt",
          "name" : "http://www.digitalmunition.com/DMA%5B2006-0313a%5D.txt",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/980084",
          "name" : "VU#980084",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.osvdb.org/23872",
          "name" : "23872",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/427601/100/0/threaded",
          "name" : "20060314 DMA[2006-0313a] - 'Apple OSX Mail.app RFC1740 Real Name Buffer Overflow'",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/17081",
          "name" : "17081",
          "refsource" : "BID",
          "tags" : [ "Exploit", "Patch" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0949",
          "name" : "ADV-2006-0949",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/25209",
          "name" : "macosx-mail-attachment-bo(25209)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Buffer overflow in Mail in Apple Mac OS X 10.4 up to 10.4.5, when patched with Security Update 2006-001, allows remote attackers to execute arbitrary code via a long Real Name value in an e-mail attachment sent in AppleDouble format, which triggers the overflow when the user double-clicks on an attachment."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.5:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:H/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "HIGH",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.1
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 4.9,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2006-03-14T11:02Z",
    "lastModifiedDate" : "2018-10-19T15:44Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0397",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apple",
            "product" : {
              "product_data" : [ {
                "product_name" : "mac_os_x",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.5",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "mac_os_x_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.5",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-94"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://docs.info.apple.com/article.html?artnum=303453",
          "name" : "http://docs.info.apple.com/article.html?artnum=303453",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://lists.apple.com/archives/security-announce/2006/Mar/msg00001.html",
          "name" : "APPLE-SA-2006-03-13",
          "refsource" : "APPLE",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/19129",
          "name" : "19129",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1015760",
          "name" : "1015760",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/23869",
          "name" : "23869",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0949",
          "name" : "ADV-2006-0949",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/25269",
          "name" : "macosx-safefiletype-command-execution(25269)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in Safari, LaunchServices, and/or CoreTypes in Apple Mac OS X 10.4 up to 10.4.5 allows attackers to trick a user into opening an application that appears to be a safe file type. NOTE: due to the lack of specific information in the vendor advisory, it is not clear how CVE-2006-0397, CVE-2006-0398, and CVE-2006-0399 are different."
        }, {
          "lang" : "en",
          "value" : "Per Hyperlink 894663:\r\nVendor description specifies that the file is automatically opened by the application: Safari could automatically open a file which appears to be a safe file type."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.5:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-03-14T11:02Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0398",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apple",
            "product" : {
              "product_data" : [ {
                "product_name" : "mac_os_x",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.5",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "mac_os_x_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.5",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-94"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://docs.info.apple.com/article.html?artnum=303453",
          "name" : "http://docs.info.apple.com/article.html?artnum=303453",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://lists.apple.com/archives/security-announce/2006/Mar/msg00001.html",
          "name" : "APPLE-SA-2006-03-13",
          "refsource" : "APPLE",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/19129",
          "name" : "19129",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1015760",
          "name" : "1015760",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/23870",
          "name" : "23870",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0949",
          "name" : "ADV-2006-0949",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/25269",
          "name" : "macosx-safefiletype-command-execution(25269)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in Safari, LaunchServices, and/or CoreTypes in Apple Mac OS X 10.4 up to 10.4.5 allows attackers to trick a user into opening an application that appears to be a safe file type. NOTE: due to the lack of specific information in the vendor advisory, it is not clear how CVE-2006-0397, CVE-2006-0398, and CVE-2006-0399 are different."
        }, {
          "lang" : "en",
          "value" : "Hyperlink Record 894667 specifies: Safari could automatically open a file which appears to be a safe file type, such as an image or movie, but is actually an application."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.5:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-03-14T11:02Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0399",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apple",
            "product" : {
              "product_data" : [ {
                "product_name" : "mac_os_x",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.5",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "mac_os_x_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.5",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-94"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://docs.info.apple.com/article.html?artnum=303453",
          "name" : "http://docs.info.apple.com/article.html?artnum=303453",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://lists.apple.com/archives/security-announce/2006/Mar/msg00001.html",
          "name" : "APPLE-SA-2006-03-13",
          "refsource" : "APPLE",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/19129",
          "name" : "19129",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1015760",
          "name" : "1015760",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/23871",
          "name" : "23871",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0949",
          "name" : "ADV-2006-0949",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/25269",
          "name" : "macosx-safefiletype-command-execution(25269)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in Safari, LaunchServices, and/or CoreTypes in Apple Mac OS X 10.4 up to 10.4.5 allows attackers to trick a user into opening an application that appears to be a safe file type. NOTE: due to the lack of specific information in the vendor advisory, it is not clear how CVE-2006-0397, CVE-2006-0398, and CVE-2006-0399 are different."
        }, {
          "lang" : "en",
          "value" : "Per Hyperlink Record 894671:\r\nSafari could automatically open a file which appears to be a safe file type, such as an image or movie, but is actually an application."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.5:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-03-14T11:02Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0400",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apple",
            "product" : {
              "product_data" : [ {
                "product_name" : "mac_os_x",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.5",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "mac_os_x_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.4.5",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://docs.info.apple.com/article.html?artnum=303453",
          "name" : "http://docs.info.apple.com/article.html?artnum=303453",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://lists.apple.com/archives/security-announce/2006/Mar/msg00001.html",
          "name" : "APPLE-SA-2006-03-13",
          "refsource" : "APPLE",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/19129",
          "name" : "19129",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1015763",
          "name" : "1015763",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/23873",
          "name" : "23873",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/17082",
          "name" : "17082",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0949",
          "name" : "ADV-2006-0949",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/25208",
          "name" : "macosx-sameorigin-policy-bypass(25208)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "CoreTypes in Apple Mac OS X 10.4 up to 10.4.5 allows remote attackers to bypass the same-origin policy and execute Javascript in other domains via unknown vectors involving \"crafted archives.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.5:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-03-14T11:02Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0401",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apple",
            "product" : {
              "product_data" : [ {
                "product_name" : "mac_os_x",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.4.5",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "mac_os_x_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.4.5",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://docs.info.apple.com/article.html?artnum=303567",
          "name" : "http://docs.info.apple.com/article.html?artnum=303567",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/19462",
          "name" : "19462",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1015859",
          "name" : "1015859",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/24399",
          "name" : "24399",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/17364",
          "name" : "17364",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/1215",
          "name" : "ADV-2006-1215",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/25620",
          "name" : "macosx-firmware-password-bypass(25620)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in Mac OS X before 10.4.6, when running on an Intel-based computer, allows attackers with physical access to bypass the firmware password and log on in Single User Mode via unspecified vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.5:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 4.6
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 3.9,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-04-05T10:04Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0402",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "jason_geiger",
            "product" : {
              "product_data" : [ {
                "product_name" : "zoph",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.3.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.4",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18563",
          "name" : "18563",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/19153",
          "name" : "19153",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://sourceforge.net/project/shownotes.php?group_id=69353&release_id=387320",
          "name" : "http://sourceforge.net/project/shownotes.php?group_id=69353&release_id=387320",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.debian.org/security/2006/dsa-989",
          "name" : "DSA-989",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/22743",
          "name" : "22743",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16347",
          "name" : "16347",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0297",
          "name" : "ADV-2006-0297",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24264",
          "name" : "zoph-sql-injection(24264)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in Zoph before 0.5pre1 allows remote attackers to execute arbitrary SQL commands."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:jason_geiger:zoph:0.3.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:jason_geiger:zoph:0.4:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-25T02:03Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0403",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "e-moblog",
            "product" : {
              "product_data" : [ {
                "product_name" : "e-moblog",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://attrition.org/pipermail/vim/2006-January/000511.html",
          "name" : "20060125 The parameter in e-moBLOG is \"monthy\" [sic]",
          "refsource" : "VIM",
          "tags" : [ ]
        }, {
          "url" : "http://evuln.com/vulns/43/summary.html",
          "name" : "http://evuln.com/vulns/43/summary.html",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18567",
          "name" : "18567",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/370",
          "name" : "370",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1015524",
          "name" : "1015524",
          "refsource" : "SECTRACK",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.osvdb.org/22700",
          "name" : "22700",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/22701",
          "name" : "22701",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/422938/100/0/threaded",
          "name" : "20060122 [eVuln] e-moBLOG SQL Injection Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16344",
          "name" : "16344",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0296",
          "name" : "ADV-2006-0296",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24245",
          "name" : "emoblog-index-sql-injection(24245)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple SQL injection vulnerabilities in e-moBLOG 1.3 allow remote attackers to execute arbitrary SQL commands via the (1) monthy parameter to index.php or (2) login parameter to admin/index.php. NOTE: some sources have reported item 1 as involving the \"monthly\" parameter, but this is incorrect."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:e-moblog:e-moblog:1.3:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-25T02:03Z",
    "lastModifiedDate" : "2018-10-19T15:44Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0404",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "mike_macgirvin",
            "product" : {
              "product_data" : [ {
                "product_name" : "note-a-day_weblog",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://archives.neohapsis.com/archives/bugtraq/2006-01/0389.html",
          "name" : "20060122 [eVuln] Note-A-Day Weblog Sensitive Information Disclosure",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://evuln.com/vulns/44/summary.html",
          "name" : "http://evuln.com/vulns/44/summary.html",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18566",
          "name" : "18566",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/371",
          "name" : "371",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1015539",
          "name" : "1015539",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/22699",
          "name" : "22699",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0299",
          "name" : "ADV-2006-0299",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24270",
          "name" : "noteaday-archive-information-disclosure(24270)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Note-A-Day Weblog 2.2 stores sensitive data under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information via a direct request to archive/.phpass-admin, which contains encrypted passwords."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mike_macgirvin:note-a-day_weblog:2.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-25T02:03Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0405",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "libtiff",
            "product" : {
              "product_data" : [ {
                "product_name" : "libtiff",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.8.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://bugzilla.remotesensing.org/show_bug.cgi?id=1029",
          "name" : "http://bugzilla.remotesensing.org/show_bug.cgi?id=1029",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://bugzilla.remotesensing.org/show_bug.cgi?id=1034",
          "name" : "http://bugzilla.remotesensing.org/show_bug.cgi?id=1034",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18587",
          "name" : "18587",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/20345",
          "name" : "20345",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.gentoo.org/security/en/glsa/glsa-200605-17.xml",
          "name" : "GLSA-200605-17",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/18172",
          "name" : "18172",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0302",
          "name" : "ADV-2006-0302",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24275",
          "name" : "libtiff-tiffvsetfield-dos(24275)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The TIFFFetchShortPair function in tif_dirread.c in libtiff 3.8.0 allows remote attackers to cause a denial of service (application crash) via a crafted TIFF image that triggers a NULL pointer dereference, possibly due to changes in type declarations and/or the TIFFVSetField function."
        }, {
          "lang" : "en",
          "value" : "Per: http://cwe.mitre.org/data/definitions/476.html\r\n'CWE-476: NULL Pointer Dereference'"
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:libtiff:libtiff:3.8.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-25T02:03Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0406",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "mybulletinboard",
            "product" : {
              "product_data" : [ {
                "product_name" : "mybulletinboard",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18577",
          "name" : "18577",
          "refsource" : "SECUNIA",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/22736",
          "name" : "22736",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/422227/100/0/threaded",
          "name" : "20060114 MyBB 1.0.2 Sniffing table perfix bug in search.php",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24272",
          "name" : "mybb-search-information-disclosure(24272)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "search.php in MyBB 1.0.2 allows remote attackers to obtain sensitive information via a certain search request that reveals the table prefix in a SQL error message, possibly due to invalid parameters."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mybulletinboard:mybulletinboard:1.0.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-25T02:03Z",
    "lastModifiedDate" : "2018-10-19T15:44Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0407",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "azbb",
            "product" : {
              "product_data" : [ {
                "product_name" : "az_bulletin_board",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.0rc1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.0rc2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.00",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://kapda.ir/advisory-236.html",
          "name" : "http://kapda.ir/advisory-236.html",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18565",
          "name" : "18565",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/423353/100/0/threaded",
          "name" : "20060123 Azbb v1.1.00 Cross-Site Scripting",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/423363/100/0/threaded",
          "name" : "20060128 [CORRECTIONS AND ADDITIONS ]Azbb v1.1.00 Cross-Site Scripting",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/427076/100/0/threaded",
          "name" : "20060308 Re: [CORRECTIONS AND ADDITIONS ]Azbb v1.1.00 Cross-Site Scripting",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/427076/30/6510/threaded",
          "name" : "20060308 Re: [CORRECTIONS AND ADDITIONS ]Azbb v1.1.00 Cross-Site Scripting",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/427194/100/0/threaded",
          "name" : "20060309 Re: Re: [CORRECTIONS AND ADDITIONS ]Azbb v1.1.00 Cross-Site Scripting",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16351",
          "name" : "16351",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0298",
          "name" : "ADV-2006-0298",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24274",
          "name" : "azbulletinboard-post-xss(24274)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in post.php in AZ Bulletin Board (AZbb) 1.1.00 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) nickname parameter and (2) an iframe tag in the topic parameter.  NOTE: the original disclosure specified the name parameter, but a correction was later provided. NOTE: followup posts have both disputed and confirmed the original claim."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:azbb:az_bulletin_board:1.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:azbb:az_bulletin_board:1.0.0rc1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:azbb:az_bulletin_board:1.0.0rc2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:azbb:az_bulletin_board:1.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:azbb:az_bulletin_board:1.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:azbb:az_bulletin_board:1.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:azbb:az_bulletin_board:1.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:azbb:az_bulletin_board:1.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:azbb:az_bulletin_board:1.0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:azbb:az_bulletin_board:1.0.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:azbb:az_bulletin_board:1.0.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:azbb:az_bulletin_board:1.0.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:azbb:az_bulletin_board:1.0.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:azbb:az_bulletin_board:1.0.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:azbb:az_bulletin_board:1.0.12:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:azbb:az_bulletin_board:1.1.00:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-25T02:03Z",
    "lastModifiedDate" : "2018-10-19T15:44Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0408",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "sun",
            "product" : {
              "product_data" : [ {
                "product_name" : "grid_engine",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://gridengine.sunsource.net/project/gridengine/60patches.txt",
          "name" : "http://gridengine.sunsource.net/project/gridengine/60patches.txt",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18580",
          "name" : "18580",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1015531",
          "name" : "1015531",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16366",
          "name" : "16366",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0308",
          "name" : "ADV-2006-0308",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24281",
          "name" : "sge-rsh-gain-privileges(24281)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "rsh utility in Sun Grid Engine (SGE) before 6.0u7_1 allows local users to gain privileges and execute arbitrary code via unspecified vectors, possibly involving command line arguments."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sun:grid_engine:6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sun:grid_engine:6.0:update1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sun:grid_engine:6.0:update2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sun:grid_engine:6.0:update3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sun:grid_engine:6.0:update4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sun:grid_engine:6.0:update5:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sun:grid_engine:6.0:update6:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sun:grid_engine:6.0:update7:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.2
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 3.9,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-25T02:03Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0409",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "pixelpost",
            "product" : {
              "product_data" : [ {
                "product_name" : "photoblog",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.4.3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://evuln.com/vulns/45/summary.html",
          "name" : "http://evuln.com/vulns/45/summary.html",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18572",
          "name" : "18572",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1015529",
          "name" : "1015529",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/423384/100/0/threaded",
          "name" : "20060123 [eVuln] Pixelpost Photoblog XSS Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16362",
          "name" : "16362",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0309",
          "name" : "ADV-2006-0309",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24261",
          "name" : "pixelpost-index-xss(24261)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in index.php in Pixelpost Photoblog 1.4.3 allows remote attackers to inject arbitrary web script or HTML via the \"Add Comment\" field in a comment popup."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pixelpost:photoblog:1.4.3:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-25T02:03Z",
    "lastModifiedDate" : "2018-10-19T15:44Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0410",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "john_lim",
            "product" : {
              "product_data" : [ {
                "product_name" : "adodb",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.66",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.68",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.70",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18575",
          "name" : "18575",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18732",
          "name" : "18732",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18745",
          "name" : "18745",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/19555",
          "name" : "19555",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/19590",
          "name" : "19590",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/19591",
          "name" : "19591",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/19691",
          "name" : "19691",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://sourceforge.net/project/shownotes.php?release_id=387862&group_id=42718",
          "name" : "http://sourceforge.net/project/shownotes.php?release_id=387862&group_id=42718",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.debian.org/security/2006/dsa-1029",
          "name" : "DSA-1029",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2006/dsa-1030",
          "name" : "DSA-1030",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2006/dsa-1031",
          "name" : "DSA-1031",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.gentoo.org/security/en/glsa/glsa-200602-02.xml",
          "name" : "GLSA-200602-02",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://www.gentoo.org/security/en/glsa/glsa-200604-07.xml",
          "name" : "GLSA-200604-07",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/22705",
          "name" : "22705",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16364",
          "name" : "16364",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0315",
          "name" : "ADV-2006-0315",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0448",
          "name" : "ADV-2006-0448",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24314",
          "name" : "adodb-postgresql-sql-injection(24314)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in ADOdb before 4.71, when using PostgreSQL, allows remote attackers to execute arbitrary SQL commands via unspecified attack vectors involving binary strings."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:john_lim:adodb:4.66:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:john_lim:adodb:4.68:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:john_lim:adodb:4.70:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-25T02:03Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0411",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "claroline",
            "product" : {
              "product_data" : [ {
                "product_name" : "claroline",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.7.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18588",
          "name" : "18588",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/422482",
          "name" : "20060120 Claroline 1.7.2, sso identification vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16341",
          "name" : "16341",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0320",
          "name" : "ADV-2006-0320",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24326",
          "name" : "claroline-cookie-bypass-security(24326)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "claro_init_local.inc.php in Claroline 1.7.2 uses guessable session cookies (MD5 hash of connection time), which allows remote attackers to hijack sessions and possibly gain administrative privileges."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:claroline:claroline:1.7.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-25T11:03Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0412",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "gencbeyin_web_programlama",
            "product" : {
              "product_data" : [ {
                "product_name" : "cybershop",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://archives.neohapsis.com/archives/bugtraq/2006-01/0064.html",
          "name" : "20060105 CyberShop User Login Sql Injection",
          "refsource" : "BUGTRAQ",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.osvdb.org/22365",
          "name" : "22365",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24005",
          "name" : "cybershop-login-sql-injection(24005)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in CyberShop allows remote attackers to execute arbitrary SQL commands and bypass authentication via the username parameter in a login action."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:gencbeyin_web_programlama:cybershop:-:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-25T11:03Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0413",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "newsphp",
            "product" : {
              "product_data" : [ {
                "product_name" : "newsphp",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18624",
          "name" : "18624",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/22717",
          "name" : "22717",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/423129/100/0/threaded",
          "name" : "20060122 Newsphp Multiple SQL Injection Vulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16339",
          "name" : "16339",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0341",
          "name" : "ADV-2006-0341",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24320",
          "name" : "newsphp-index-sql-injection(24320)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple SQL injection vulnerabilities in index.php in NewsPHP allow remote attackers to execute arbitrary SQL commands via the (1) discuss, (2) tim, (3) id, (4) last, and (5) limit parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:newsphp:newsphp:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-25T11:03Z",
    "lastModifiedDate" : "2018-10-19T15:44Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0414",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "tor",
            "product" : {
              "product_data" : [ {
                "product_name" : "tor",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.0.2_pre13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.0.2_pre14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.0.2_pre15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.0.2_pre16",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.0.2_pre17",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.0.2_pre18",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.0.2_pre19",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.0.2_pre20",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.0.2_pre21",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.0.2_pre22",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.0.2_pre23",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.0.2_pre24",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.0.2_pre25",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.0.2_pre26",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.0.2_pre27",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.0.6.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.0.6.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.0.7.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.0.7.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.0.7.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.0.8.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.0.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.0.9.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.0.9.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.0.9.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.0.9.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.0.9.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.0.9.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.0.9.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.0.9.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.0.9.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.0.9.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.1.0.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.1.0.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.1.0.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.1.0.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.1.0.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.1.0.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.1.0.16",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.1.0.17",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.1.1.1_alpha",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.1.1.2_alpha",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.1.1.3_alpha",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.1.1.4_alpha",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.1.1.5_alpha",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.1.1.6_alpha",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.1.1.7_alpha",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.1.1.8_alpha",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.1.1.9_alpha",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.1.1.10_alpha",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://archives.seul.org/or/announce/Jan-2006/msg00001.html",
          "name" : "http://archives.seul.org/or/announce/Jan-2006/msg00001.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18576",
          "name" : "18576",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/20514",
          "name" : "20514",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://security.gentoo.org/glsa/glsa-200606-04.xml",
          "name" : "GLSA-200606-04",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://tor.eff.org/cvs/tor/ChangeLog",
          "name" : "http://tor.eff.org/cvs/tor/ChangeLog",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/22689",
          "name" : "22689",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/18323",
          "name" : "18323",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/19795",
          "name" : "19795",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24285",
          "name" : "tor-service-information-disclosure(24285)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Tor before 0.1.1.20 allows remote attackers to identify hidden services via a malicious Tor server that attempts a large number of accesses of the hidden service, which eventually causes a circuit to be built through the malicious server."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tor:tor:0.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tor:tor:0.0.2_pre13:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tor:tor:0.0.2_pre14:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tor:tor:0.0.2_pre15:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tor:tor:0.0.2_pre16:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tor:tor:0.0.2_pre17:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tor:tor:0.0.2_pre18:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tor:tor:0.0.2_pre19:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tor:tor:0.0.2_pre20:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tor:tor:0.0.2_pre21:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tor:tor:0.0.2_pre22:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tor:tor:0.0.2_pre23:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tor:tor:0.0.2_pre24:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tor:tor:0.0.2_pre25:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tor:tor:0.0.2_pre26:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tor:tor:0.0.2_pre27:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tor:tor:0.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tor:tor:0.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tor:tor:0.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tor:tor:0.0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tor:tor:0.0.6.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tor:tor:0.0.6.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tor:tor:0.0.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tor:tor:0.0.7.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tor:tor:0.0.7.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tor:tor:0.0.7.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tor:tor:0.0.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tor:tor:0.0.8.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tor:tor:0.0.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tor:tor:0.0.9.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tor:tor:0.0.9.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tor:tor:0.0.9.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tor:tor:0.0.9.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tor:tor:0.0.9.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tor:tor:0.0.9.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tor:tor:0.0.9.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tor:tor:0.0.9.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tor:tor:0.0.9.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tor:tor:0.0.9.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tor:tor:0.1.0.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tor:tor:0.1.0.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tor:tor:0.1.0.12:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tor:tor:0.1.0.13:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tor:tor:0.1.0.14:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tor:tor:0.1.0.15:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tor:tor:0.1.0.16:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tor:tor:0.1.0.17:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tor:tor:0.1.1.1_alpha:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tor:tor:0.1.1.2_alpha:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tor:tor:0.1.1.3_alpha:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tor:tor:0.1.1.4_alpha:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tor:tor:0.1.1.5_alpha:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tor:tor:0.1.1.6_alpha:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tor:tor:0.1.1.7_alpha:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tor:tor:0.1.1.8_alpha:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tor:tor:0.1.1.9_alpha:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tor:tor:0.1.1.10_alpha:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-25T11:03Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0415",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "sleeperchat",
            "product" : {
              "product_data" : [ {
                "product_name" : "sleeperchat",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.3f",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://securitytracker.com/id?1015525",
          "name" : "1015525",
          "refsource" : "SECTRACK",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.osvdb.org/22784",
          "name" : "22784",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16363",
          "name" : "16363",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24300",
          "name" : "sleeperchat-index-xss(24300)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in index.php in SleeperChat 0.3f and earlier allows remote attackers to inject arbitrary web script or HTML via the pseudo parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sleeperchat:sleeperchat:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "0.3f"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-25T11:03Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0416",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "sleeperchat",
            "product" : {
              "product_data" : [ {
                "product_name" : "sleeperchat",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.3f",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-287"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://securitytracker.com/id?1015525",
          "name" : "1015525",
          "refsource" : "SECTRACK",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24357",
          "name" : "sleeperchat-txt-security-bypass(24357)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SleeperChat 0.3f and earlier allows remote attackers to bypass authentication and create new entries via the txt parameter to (1) chat_no.php and (2) chat_if.php."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sleeperchat:sleeperchat:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "0.3f"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-25T11:03Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0417",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "mywebland",
            "product" : {
              "product_data" : [ {
                "product_name" : "minibloggie",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://evuln.com/vulns/47/summary.html",
          "name" : "http://evuln.com/vulns/47/summary.html",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18604",
          "name" : "18604",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1015534",
          "name" : "1015534",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/22729",
          "name" : "22729",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/423126/100/0/threaded",
          "name" : "20060124 [eVuln] miniBloggie Authentication Bypass",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16367",
          "name" : "16367",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0310",
          "name" : "ADV-2006-0310",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24280",
          "name" : "minibloggie-login-sql-injection(24280)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in login.php in miniBloggie 1.0 and earlier, when gpc_magic_quotes is disabled, allows remote attackers to execute arbitrary SQL commands and bypass authentication via the (1) username and (2) password parameters."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mywebland:minibloggie:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.0"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-25T11:03Z",
    "lastModifiedDate" : "2018-10-19T15:44Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0418",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "topcmm_computing",
            "product" : {
              "product_data" : [ {
                "product_name" : "123_flash_chat_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/archive/1/423164/100/0/threaded",
          "name" : "20060124 [ISecAuditors Advisories] Arbitrary flash code remote execution in 123flashchat",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16360",
          "name" : "16360",
          "refsource" : "BID",
          "tags" : [ "Exploit", "Patch" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Eval injection vulnerability in 123 Flash Chat Server 5.0 and 5.1 allows attackers to execute arbitrary code via a crafted username."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:topcmm_computing:123_flash_chat_server:5.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:topcmm_computing:123_flash_chat_server:5.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-25T11:03Z",
    "lastModifiedDate" : "2018-10-19T15:44Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0419",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "bea",
            "product" : {
              "product_data" : [ {
                "product_name" : "weblogic_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://dev2dev.bea.com/pub/advisory/163",
          "name" : "BEA06-81.01",
          "refsource" : "BEA",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1015528",
          "name" : "1015528",
          "refsource" : "SECTRACK",
          "tags" : [ "Patch" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "BEA WebLogic Server and WebLogic Express 9.0, 8.1 through SP5, and 7.0 through SP6 allows anonymous binds to the embedded LDAP server, which allows remote attackers to read user entries or cause a denial of service (unspecified) via a large number of connections."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:7.0:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:7.0:sp1:express:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:7.0:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:7.0:sp2:express:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:7.0:sp3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:7.0:sp3:express:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:7.0:sp4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:7.0:sp4:express:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:7.0:sp5:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:7.0:sp5:express:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:7.0:sp6:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:7.0:sp6:express:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:8.1:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:8.1:sp1:express:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:8.1:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:8.1:sp2:express:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:8.1:sp3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:8.1:sp3:express:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:8.1:sp4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:8.1:sp4:express:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:8.1:sp5:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:8.1:sp5:express:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:9.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:9.0:*:express:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.4
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-25T23:07Z",
    "lastModifiedDate" : "2008-09-05T20:59Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0420",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "bea",
            "product" : {
              "product_data" : [ {
                "product_name" : "weblogic_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://dev2dev.bea.com/pub/advisory/164",
          "name" : "BEA06-106.01",
          "refsource" : "BEA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1015528",
          "name" : "1015528",
          "refsource" : "SECTRACK",
          "tags" : [ "Patch" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "BEA WebLogic Server and WebLogic Express 8.1 through SP4 and 7.0 through SP6 does not properly handle when servlets use relative forwarding, which allows remote attackers to cause a denial of service (slowdown) via unknown attack vectors that cause \"looping stack overflow errors.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:7.0:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:7.0:sp1:express:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:7.0:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:7.0:sp2:express:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:7.0:sp3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:7.0:sp3:express:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:7.0:sp4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:7.0:sp4:express:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:7.0:sp5:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:7.0:sp5:express:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:7.0:sp6:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:7.0:sp6:express:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:8.1:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:8.1:sp1:express:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:8.1:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:8.1:sp2:express:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:8.1:sp3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:8.1:sp3:express:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:8.1:sp4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:8.1:sp4:express:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-25T23:07Z",
    "lastModifiedDate" : "2008-09-05T20:59Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0421",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "bea",
            "product" : {
              "product_data" : [ {
                "product_name" : "weblogic_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://dev2dev.bea.com/pub/advisory/165",
          "name" : "BEA06-108.00",
          "refsource" : "BEA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18581",
          "name" : "18581",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1015528",
          "name" : "1015528",
          "refsource" : "SECTRACK",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16358",
          "name" : "16358",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0313",
          "name" : "ADV-2006-0313",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24286",
          "name" : "weblogic-cross-domain-management(24286)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "By design, BEA WebLogic Server and WebLogic Express 7.0 and 6.1, when creating multiple domains from the same WebLogic instance on the same machine, allows administrators of any created domain to access other created domains, which could allow administrators to gain privileges that were not intended."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:6.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:6.1:*:express:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:7.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:7.0:*:express:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 4.6
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 3.9,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-25T23:07Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0422",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "bea",
            "product" : {
              "product_data" : [ {
                "product_name" : "weblogic_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://dev2dev.bea.com/pub/advisory/166",
          "name" : "BEA06-109.00",
          "refsource" : "BEA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18592",
          "name" : "18592",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1015528",
          "name" : "1015528",
          "refsource" : "SECTRACK",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16358",
          "name" : "16358",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0313",
          "name" : "ADV-2006-0313",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24294",
          "name" : "weblogic-java-mbean-access(24294)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple unspecified vulnerabilities in BEA WebLogic Server and WebLogic Express 8.1 through SP4, 7.0 through SP6, and 6.1 through SP7 allow remote attackers to access MBean attributes or cause an unspecified denial of service via unknown attack vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:6.1:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:6.1:sp1:express:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:6.1:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:6.1:sp2:express:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:6.1:sp3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:6.1:sp3:express:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:6.1:sp4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:6.1:sp4:express:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:6.1:sp5:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:6.1:sp5:express:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:6.1:sp6:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:6.1:sp7:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:6.1:sp7:express:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:7.0:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:7.0:sp1:express:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:7.0:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:7.0:sp2:express:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:7.0:sp3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:7.0:sp3:express:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:7.0:sp4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:7.0:sp4:express:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:7.0:sp5:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:7.0:sp5:express:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:7.0:sp6:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:7.0:sp6:express:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:8.1:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:8.1:sp1:express:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:8.1:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:8.1:sp2:express:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:8.1:sp3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:8.1:sp3:express:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:8.1:sp4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:8.1:sp4:express:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.4
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-25T23:07Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0423",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "weblogic_portal",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://dev2dev.bea.com/pub/advisory/167",
          "name" : "BEA06-110.00",
          "refsource" : "BEA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://dev2dev.bea.com/pub/advisory/262",
          "name" : "BEA08-110.01",
          "refsource" : "BEA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18593",
          "name" : "18593",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1015528",
          "name" : "1015528",
          "refsource" : "SECTRACK",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16358",
          "name" : "16358",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0312",
          "name" : "ADV-2006-0312",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0613",
          "name" : "ADV-2008-0613",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24284",
          "name" : "weblogicportal-config-info-disclosure(24284)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/40705",
          "name" : "weblogic-portal-config-info-disclosure(40705)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "BEA WebLogic Portal 8.1 through SP3 stores the password for the RDBMS Authentication provider in cleartext in the config.xml file, which allows attackers to gain privileges."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:weblogic_portal:8.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:weblogic_portal:8.1:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:weblogic_portal:8.1:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:weblogic_portal:8.1:sp3:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-25T23:07Z",
    "lastModifiedDate" : "2018-10-30T16:25Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0424",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "bea",
            "product" : {
              "product_data" : [ {
                "product_name" : "weblogic_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://dev2dev.bea.com/pub/advisory/168",
          "name" : "BEA06-111.00",
          "refsource" : "BEA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18592",
          "name" : "18592",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1015528",
          "name" : "1015528",
          "refsource" : "SECTRACK",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.osvdb.org/22776",
          "name" : "22776",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16358",
          "name" : "16358",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0313",
          "name" : "ADV-2006-0313",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24295",
          "name" : "weblogic-server-log-disclosure(24295)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "BEA WebLogic Server and WebLogic Express 8.1 through SP4, 7.0 through SP6, and 6.1 through SP7 allows remote authenticated guest users to read the server log and obtain sensitive configuration information."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:6.1:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:6.1:sp1:express:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:6.1:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:6.1:sp2:express:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:6.1:sp3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:6.1:sp3:express:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:6.1:sp4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:6.1:sp4:express:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:6.1:sp5:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:6.1:sp5:express:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:6.1:sp6:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:6.1:sp7:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:6.1:sp7:express:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:7.0:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:7.0:sp1:express:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:7.0:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:7.0:sp2:express:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:7.0:sp3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:7.0:sp3:express:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:7.0:sp4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:7.0:sp4:express:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:7.0:sp5:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:7.0:sp5:express:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:7.0:sp6:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:7.0:sp6:express:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:8.1:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:8.1:sp1:express:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:8.1:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:8.1:sp2:express:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:8.1:sp3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:8.1:sp3:express:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:8.1:sp4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:8.1:sp4:express:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-25T23:07Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0425",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "weblogic_portal",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://dev2dev.bea.com/pub/advisory/169",
          "name" : "BEA06-112.00",
          "refsource" : "BEA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18593",
          "name" : "18593",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1015528",
          "name" : "1015528",
          "refsource" : "SECTRACK",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16358",
          "name" : "16358",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0312",
          "name" : "ADV-2006-0312",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24297",
          "name" : "weblogic-deployment-descriptor-disclosure(24297)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "BEA WebLogic Portal 8.1 through SP4 allows remote attackers to obtain the source for a deployment descriptor file via unknown vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:weblogic_portal:8.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:weblogic_portal:8.1:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:weblogic_portal:8.1:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:weblogic_portal:8.1:sp3:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-25T23:07Z",
    "lastModifiedDate" : "2018-10-30T16:25Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0426",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "bea",
            "product" : {
              "product_data" : [ {
                "product_name" : "weblogic_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://dev2dev.bea.com/pub/advisory/170",
          "name" : "BEA06-113.00",
          "refsource" : "BEA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18592",
          "name" : "18592",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1015528",
          "name" : "1015528",
          "refsource" : "SECTRACK",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.osvdb.org/22775",
          "name" : "22775",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16358",
          "name" : "16358",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0313",
          "name" : "ADV-2006-0313",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24290",
          "name" : "weblogic-password-information-disclosure(24290)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "BEA WebLogic Server and WebLogic Express 8.1 through SP4, when configuration auditing is enabled and a password change occurs, stores the old and new passwords in cleartext in the DefaultAuditRecorder.log file, which could allow attackers to gain privileges."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:8.1:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:8.1:sp1:express:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:8.1:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:8.1:sp2:express:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:8.1:sp3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:8.1:sp3:express:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:8.1:sp4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:8.1:sp4:express:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-25T23:07Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0427",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "bea",
            "product" : {
              "product_data" : [ {
                "product_name" : "weblogic_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://dev2dev.bea.com/pub/advisory/171",
          "name" : "BEA06-114.00",
          "refsource" : "BEA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18592",
          "name" : "18592",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1015528",
          "name" : "1015528",
          "refsource" : "SECTRACK",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.osvdb.org/22774",
          "name" : "22774",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16358",
          "name" : "16358",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0313",
          "name" : "ADV-2006-0313",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24291",
          "name" : "weblogic-servlets-obtain-information(24291)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in BEA WebLogic Server and WebLogic Express 9.0 and 8.1 through SP5 allows malicious EJBs or servlet applications to decrypt system passwords, possibly by accessing functionality that should have been restricted."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:8.1:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:8.1:sp1:express:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:8.1:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:8.1:sp2:express:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:8.1:sp3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:8.1:sp3:express:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:8.1:sp4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:8.1:sp4:express:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:8.1:sp5:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:8.1:sp5:express:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:9.0:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:9.0:sp1:express:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:9.0:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:9.0:sp2:express:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:9.0:sp3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:9.0:sp3:express:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:9.0:sp4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:9.0:sp4:express:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:9.0:sp5:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:9.0:sp5:express:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 2.1
        },
        "severity" : "LOW",
        "exploitabilityScore" : 3.9,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-25T23:07Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0428",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "weblogic_portal",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://dev2dev.bea.com/pub/advisory/172",
          "name" : "BEA06-115.00",
          "refsource" : "BEA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18593",
          "name" : "18593",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1015528",
          "name" : "1015528",
          "refsource" : "SECTRACK",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.osvdb.org/22767",
          "name" : "22767",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16358",
          "name" : "16358",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0312",
          "name" : "ADV-2006-0312",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24293",
          "name" : "weblogic-wsrp-gain-access(24293)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in BEA WebLogic Portal 8.1 SP3 through SP5, when using Web Services Remote Portlets (WSRP), allows remote attackers to access restricted web resources via crafted URLs."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:weblogic_portal:8.1:sp3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:weblogic_portal:8.1:sp4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:weblogic_portal:8.1:sp5:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-25T23:07Z",
    "lastModifiedDate" : "2018-10-30T16:25Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0429",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "bea",
            "product" : {
              "product_data" : [ {
                "product_name" : "weblogic_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://dev2dev.bea.com/pub/advisory/173",
          "name" : "BEA06-116.00",
          "refsource" : "BEA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18592",
          "name" : "18592",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1015528",
          "name" : "1015528",
          "refsource" : "SECTRACK",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.osvdb.org/22773",
          "name" : "22773",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16358",
          "name" : "16358",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0313",
          "name" : "ADV-2006-0313",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24298",
          "name" : "weblogic-security-provider-weakness(24298)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "BEA WebLogic Server and WebLogic Express 9.0 causes new security providers to appear active even if they have not been activated by a server reboot, which could cause an administrator to perform inappropriate, security-relevant actions."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:9.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:9.0:*:express:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:N/I:P/A:N",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 2.1
        },
        "severity" : "LOW",
        "exploitabilityScore" : 3.9,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-25T23:07Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0430",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "bea",
            "product" : {
              "product_data" : [ {
                "product_name" : "weblogic_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://dev2dev.bea.com/pub/advisory/174",
          "name" : "BEA06-117.00",
          "refsource" : "BEA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18592",
          "name" : "18592",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1015528",
          "name" : "1015528",
          "refsource" : "SECTRACK",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16358",
          "name" : "16358",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0313",
          "name" : "ADV-2006-0313",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24301",
          "name" : "weblogic-connection-filter-dos(24301)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Certain configurations of BEA WebLogic Server and WebLogic Express 9.0, 8.1 through SP5, and 7.0 through SP6, when connection filters are enabled, cause the server to run more slowly, which makes it easier for remote attackers to cause a denial of service (server slowdown)."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:7.0:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:7.0:sp1:express:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:7.0:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:7.0:sp2:express:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:7.0:sp3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:7.0:sp3:express:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:7.0:sp4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:7.0:sp4:express:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:7.0:sp5:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:7.0:sp5:express:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:7.0:sp6:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:7.0:sp6:express:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:8.1:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:8.1:sp1:express:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:8.1:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:8.1:sp2:express:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:8.1:sp3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:8.1:sp3:express:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:8.1:sp4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:8.1:sp4:express:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:9.0:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:9.0:sp1:express:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:9.0:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:9.0:sp2:express:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:9.0:sp3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:9.0:sp3:express:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:9.0:sp4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:9.0:sp4:express:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:9.0:sp5:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:9.0:sp5:express:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-25T23:07Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0431",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "bea",
            "product" : {
              "product_data" : [ {
                "product_name" : "weblogic_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://dev2dev.bea.com/pub/advisory/175",
          "name" : "BEA06-118.00",
          "refsource" : "BEA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18592",
          "name" : "18592",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1015528",
          "name" : "1015528",
          "refsource" : "SECTRACK",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16358",
          "name" : "16358",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0313",
          "name" : "ADV-2006-0313",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24302",
          "name" : "weblogic-ssl-identity-exposure(24302)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in BEA WebLogic Server and WebLogic Express 8.1 SP5 allows untrusted applications to obtain the server's SSL identity via unknown attack vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:8.1:sp5:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:8.1:sp5:express:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 2.1
        },
        "severity" : "LOW",
        "exploitabilityScore" : 3.9,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-25T23:07Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0432",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "bea",
            "product" : {
              "product_data" : [ {
                "product_name" : "weblogic_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://dev2dev.bea.com/pub/advisory/176",
          "name" : "BEA06-119.00",
          "refsource" : "BEA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18592",
          "name" : "18592",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1015528",
          "name" : "1015528",
          "refsource" : "SECTRACK",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16358",
          "name" : "16358",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0313",
          "name" : "ADV-2006-0313",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24299",
          "name" : "weblogic-jdni-security-weakness(24299)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in BEA WebLogic Server and WebLogic Express 9.0, when an Administrator uses the WebLogic Administration Console to add custom security policies, causes incorrect policies to be created, which prevents the server from properly protecting JNDI resources."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:9.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bea:weblogic_server:9.0:*:express:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:N/I:P/A:N",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 2.1
        },
        "severity" : "LOW",
        "exploitabilityScore" : 3.9,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-25T23:07Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0433",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "freebsd",
            "product" : {
              "product_data" : [ {
                "product_name" : "freebsd",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.4",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-06:08.sack.asc",
          "name" : "FreeBSD-SA-06:08",
          "refsource" : "FREEBSD",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18696",
          "name" : "18696",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/399",
          "name" : "399",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1015566",
          "name" : "1015566",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/22861",
          "name" : "22861",
          "refsource" : "OSVDB",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16466",
          "name" : "16466",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0409",
          "name" : "ADV-2006-0409",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24453",
          "name" : "bsd-sack-handling-dos(24453)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Selective Acknowledgement (SACK) in FreeBSD 5.3 and 5.4 does not properly handle an incoming selective acknowledgement when there is insufficient memory, which might allow remote attackers to cause a denial of service (infinite loop)."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:freebsd:freebsd:5.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:freebsd:freebsd:5.4:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-02T11:02Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0434",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "phpxplorer",
            "product" : {
              "product_data" : [ {
                "product_name" : "phpxplorer",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-22"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/archive/1/422434/100/0/threaded",
          "name" : "20060118 phpXplorer file inclusion biyosecurity.be",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16292",
          "name" : "16292",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/39982",
          "name" : "phpxplorer-sshare-directory-traversal(39982)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Directory traversal vulnerability in action.php in phpXplorer allows remote attackers to read arbitrary files via \"..\" (dot dot) sequences and null bytes in the sAction parameter, a different vulnerability than CVE-2006-0244.  NOTE: if the functionality of phpXplorer supports the upload of PHP files, then this issue would not cross privilege boundaries and would not be a vulnerability."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:phpxplorer:phpxplorer:-:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-26T11:07Z",
    "lastModifiedDate" : "2018-10-19T15:44Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0435",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "application_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.2.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.2.1s",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.2.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.2.2.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0.2.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0.2.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0.2.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0.2.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0.2.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0.3.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0.4.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0.4.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0.4.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.2.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.2.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.0.3.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.2.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.2.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.2_.0.1",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "http_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0.2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.2.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.2.1s_for_apps",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.2.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.2.2_roll_up_2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.1.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0.2.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0.3.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.2.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.grok.org.uk/pipermail/full-disclosure/2006-February/041898.html",
          "name" : "20060202 The History of the Oracle PLSQL Gateway Flaw",
          "refsource" : "FULLDISC",
          "tags" : [ ]
        }, {
          "url" : "http://lists.grok.org.uk/pipermail/full-disclosure/2006-February/041899.html",
          "name" : "20060202 More on the workaround for the unpatched Oracle PLSQL Gateway flaw",
          "refsource" : "FULLDISC",
          "tags" : [ ]
        }, {
          "url" : "http://lists.grok.org.uk/pipermail/full-disclosure/2006-January/041742.html",
          "name" : "20060125 Workaround for unpatched Oracle PLSQL Gateway flaw",
          "refsource" : "FULLDISC",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18621",
          "name" : "18621",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/19712",
          "name" : "19712",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/19859",
          "name" : "19859",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/402",
          "name" : "402",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/403",
          "name" : "403",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1015544",
          "name" : "1015544",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1015961",
          "name" : "1015961",
          "refsource" : "SECTRACK",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/169164",
          "name" : "VU#169164",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpuapr2006-090826.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpuapr2006-090826.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.oracle.com/technology/deploy/security/pdf/public_vuln_to_advisory_mapping.html",
          "name" : "http://www.oracle.com/technology/deploy/security/pdf/public_vuln_to_advisory_mapping.html",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/22719",
          "name" : "22719",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/423029/100/0/threaded",
          "name" : "20060125 Workaround for unpatched Oracle PLSQL Gateway flaw",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/423673/100/0/threaded",
          "name" : "20060131 Re: Workaround for unpatched Oracle PLSQL Gateway flaw",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/423819/100/0/threaded",
          "name" : "20060202 The History of the Oracle PLSQL Gateway Flaw",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/423822/100/0/threaded",
          "name" : "20060202 More on the workaround for the unpatched Oracle PLSQL Gateway flaw",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/424394/100/0/threaded",
          "name" : "20060208 Re: Workaround for unpatched Oracle PLSQL Gateway flaw",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/432267/100/0/threaded",
          "name" : "SSRT061148",
          "refsource" : "HP",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16384",
          "name" : "16384",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0338",
          "name" : "ADV-2006-0338",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/1397",
          "name" : "ADV-2006-1397",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/1571",
          "name" : "ADV-2006-1571",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24363",
          "name" : "oracle-plsql-command-execution(24363)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in Oracle PL/SQL (PLSQL), as used in Database Server DS 9.2.0.7 and 10.1.0.5, Application Server 1.0.2.2, 9.0.4.2, 10.1.2.0.2, 10.1.2.1.0, and 10.1.3.0.0, E-Business Suite and Applications 11.5.10, and Collaboration Suite 10.1.1, 10.1.2.0, 10.1.2.1, and 9.0.4.2, allows attackers to bypass the PLSQLExclusion list and access excluded packages and procedures, aka Vuln# PLSQL01."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_server:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_server:1.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_server:1.0.2.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_server:1.0.2.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_server:1.0.2.1s:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_server:1.0.2.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_server:1.0.2.2.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_server:9.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_server:9.0.2.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_server:9.0.2.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_server:9.0.2.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_server:9.0.2.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_server:9.0.2.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_server:9.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_server:9.0.3.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_server:9.0.4.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_server:9.0.4.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_server:9.0.4.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_server:9.2.0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_server:9.2.0.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_server:10.1.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_server:10.1.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_server:10.1.0.3.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_server:10.1.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_server:10.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_server:10.1.2.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_server:10.1.2.1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_server:10.1.2_.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:http_server:1.0.2.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:http_server:1.0.2.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:http_server:1.0.2.1s_for_apps:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:http_server:1.0.2.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:http_server:1.0.2.2_roll_up_2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:http_server:8.1.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:http_server:9.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:http_server:9.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:http_server:9.0.2.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:http_server:9.0.3.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:http_server:9.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:http_server:9.2.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-26T11:07Z",
    "lastModifiedDate" : "2018-10-19T15:44Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0436",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "hp",
            "product" : {
              "product_data" : [ {
                "product_name" : "hp-ux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11.00",
                    "version_affected" : "="
                  }, {
                    "version_value" : "11.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "11.11",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18596",
          "name" : "18596",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18600",
          "name" : "18600",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1015530",
          "name" : "1015530",
          "refsource" : "SECTRACK",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://support.avaya.com/elmodocs2/security/ASA-2006-025.htm",
          "name" : "http://support.avaya.com/elmodocs2/security/ASA-2006-025.htm",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0322",
          "name" : "ADV-2006-0322",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www2.itrc.hp.com/service/cki/docDisplay.do?docId=c00591401",
          "name" : "SSRT061099",
          "refsource" : "HP",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24318",
          "name" : "hpux-unspecified-privilege-escalation(24318)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1453",
          "name" : "oval:org.mitre.oval:def:1453",
          "refsource" : "OVAL",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1577",
          "name" : "oval:org.mitre.oval:def:1577",
          "refsource" : "OVAL",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1586",
          "name" : "oval:org.mitre.oval:def:1586",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in HP HP-UX B.11.00, B.11.04, and B.11.11 allows local users to gain privileges via unknown attack vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:hp:hp-ux:11.00:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:hp:hp-ux:11.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:hp:hp-ux:11.11:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.2
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 3.9,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-26T11:07Z",
    "lastModifiedDate" : "2017-10-11T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0437",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "phpbb_group",
            "product" : {
              "product_data" : [ {
                "product_name" : "phpbb",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0.6c",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.6d",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.7a",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.8a",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.16",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.17",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.18",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.19",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.grok.org.uk/pipermail/full-disclosure/2006-February/041920.html",
          "name" : "20060203 phpBB 2.0.19 Cross Site Request Forgeries and XSS Admin",
          "refsource" : "FULLDISC",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18693",
          "name" : "18693",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/achievement_securityalert/31",
          "name" : "20060203 phpBB 2.0.19 Cross Site Request Forgeries and XSS Admin",
          "refsource" : "SREASONRES",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://securityreason.com/securityalert/406",
          "name" : "406",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/22928",
          "name" : "22928",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0445",
          "name" : "ADV-2006-0445",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24497",
          "name" : "phpbb-referer-header-http-xss(24497)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in admin_smilies.php in phpBB 2.0.19 allows remote attackers to inject arbitrary web script or HTML via Javascript events such as \"onmouseover\" in the (1) smile_url or (2) smile_emotion parameters, which bypasses a check for \"<\" and \">\" characters."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:phpbb_group:phpbb:2.0.6c:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:phpbb_group:phpbb:2.0.6d:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:phpbb_group:phpbb:2.0.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:phpbb_group:phpbb:2.0.7a:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:phpbb_group:phpbb:2.0.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:phpbb_group:phpbb:2.0.8a:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:phpbb_group:phpbb:2.0.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:phpbb_group:phpbb:2.0.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:phpbb_group:phpbb:2.0.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:phpbb_group:phpbb:2.0.12:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:phpbb_group:phpbb:2.0.13:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:phpbb_group:phpbb:2.0.14:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:phpbb_group:phpbb:2.0.15:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:phpbb_group:phpbb:2.0.16:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:phpbb_group:phpbb:2.0.17:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:phpbb_group:phpbb:2.0.18:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:phpbb_group:phpbb:2.0.19:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-06T22:02Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0438",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "phpbb_group",
            "product" : {
              "product_data" : [ {
                "product_name" : "phpbb",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.6c",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.6d",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.7a",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.8a",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.16",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.17",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.18",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.19",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0_beta1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0_rc1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0_rc2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0_rc3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0_rc4",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.grok.org.uk/pipermail/full-disclosure/2006-February/041920.html",
          "name" : "20060203 phpBB 2.0.19 Cross Site Request Forgeries and XSS Admin",
          "refsource" : "FULLDISC",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18693",
          "name" : "18693",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/achievement_securityalert/31",
          "name" : "20060203 phpBB 2.0.19 Cross Site Request Forgeries and XSS Admin",
          "refsource" : "SREASONRES",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://securityreason.com/securityalert/406",
          "name" : "406",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/22929",
          "name" : "22929",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0445",
          "name" : "ADV-2006-0445",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24497",
          "name" : "phpbb-referer-header-http-xss(24497)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site request forgery (CSRF) vulnerability in phpBB 2.0.19, when Link to off-site Avatar or bbcode (IMG) are enabled, allows remote attackers to perform unauthorized actions as a logged in user via a link or IMG tag in a user profile, as demonstrated using links to (1) admin/admin_users.php and (2) modcp.php."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:phpbb_group:phpbb:2.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:phpbb_group:phpbb:2.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:phpbb_group:phpbb:2.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:phpbb_group:phpbb:2.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:phpbb_group:phpbb:2.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:phpbb_group:phpbb:2.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:phpbb_group:phpbb:2.0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:phpbb_group:phpbb:2.0.6c:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:phpbb_group:phpbb:2.0.6d:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:phpbb_group:phpbb:2.0.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:phpbb_group:phpbb:2.0.7a:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:phpbb_group:phpbb:2.0.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:phpbb_group:phpbb:2.0.8a:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:phpbb_group:phpbb:2.0.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:phpbb_group:phpbb:2.0.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:phpbb_group:phpbb:2.0.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:phpbb_group:phpbb:2.0.12:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:phpbb_group:phpbb:2.0.13:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:phpbb_group:phpbb:2.0.14:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:phpbb_group:phpbb:2.0.15:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:phpbb_group:phpbb:2.0.16:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:phpbb_group:phpbb:2.0.17:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:phpbb_group:phpbb:2.0.18:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:phpbb_group:phpbb:2.0.19:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:phpbb_group:phpbb:2.0_beta1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:phpbb_group:phpbb:2.0_rc1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:phpbb_group:phpbb:2.0_rc2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:phpbb_group:phpbb:2.0_rc3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:phpbb_group:phpbb:2.0_rc4:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-06T22:02Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0439",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "text_rider",
            "product" : {
              "product_data" : [ {
                "product_name" : "text_rider",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.4",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://evuln.com/vulns/46/summary.html",
          "name" : "http://evuln.com/vulns/46/summary.html",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18605",
          "name" : "18605",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1015533",
          "name" : "1015533",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/423130/100/0/threaded",
          "name" : "20060124 [eVuln] Text Rider Sensitive Information Disclosure",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0321",
          "name" : "ADV-2006-0321",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24279",
          "name" : "textrider-data-information-disclosure(24279)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Text Rider 2.4 stores sensitive data in the data directory under the web document root with insufficient access control, which allows remote attackers to obtain usernames and password hashes by directly accessing data/userlist.txt."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:text_rider:text_rider:2.4:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-26T22:03Z",
    "lastModifiedDate" : "2018-10-19T15:44Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0440",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "text_rider",
            "product" : {
              "product_data" : [ {
                "product_name" : "text_rider",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.4",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://evuln.com/vulns/46/summary.html",
          "name" : "http://evuln.com/vulns/46/summary.html",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1015533",
          "name" : "1015533",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/423130/100/0/threaded",
          "name" : "20060124 [eVuln] Text Rider Sensitive Information Disclosure",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Text Rider 2.4 allows attackers to bypass authentication and upload files without providing a valid password by obtaining the MD5 hash of the password (possibly via another vulnerability that reads it from a data file), then including the hash in a cookie."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:text_rider:text_rider:2.4:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-26T22:03Z",
    "lastModifiedDate" : "2018-10-19T15:44Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0441",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "karjasoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "sami_ftp_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://downloads.securityfocus.com/vulnerabilities/exploits/sami_ftp_poc.pl",
          "name" : "http://downloads.securityfocus.com/vulnerabilities/exploits/sami_ftp_poc.pl",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18574",
          "name" : "18574",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.critical.lt/?vulnerabilities/208",
          "name" : "http://www.critical.lt/?vulnerabilities/208",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://www.karjasoft.com/samiftp/news",
          "name" : "http://www.karjasoft.com/samiftp/news",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/423148/100/0/threaded",
          "name" : "20060124 SamiFTPd buffer overflow",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16370",
          "name" : "16370",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0317",
          "name" : "ADV-2006-0317",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24325",
          "name" : "samiftpserver-user-bo(24325)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/40675/",
          "name" : "40675",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Stack-based buffer overflow in Sami FTP Server 2.0.1 allows remote attackers to execute arbitrary code via a long USER command, which triggers the overflow when the log is viewed."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:karjasoft:sami_ftp_server:2.0.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-26T22:03Z",
    "lastModifiedDate" : "2018-10-19T15:44Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0442",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "mybb",
            "product" : {
              "product_data" : [ {
                "product_name" : "mybb",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://kapda.ir/advisory-241.html",
          "name" : "http://kapda.ir/advisory-241.html",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18603",
          "name" : "18603",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1015535",
          "name" : "1015535",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/423128/100/0/threaded",
          "name" : "20060124 [KAPDA::#25] - MyBB 1.x Cross_Site_Scripting",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16361",
          "name" : "16361",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0316",
          "name" : "ADV-2006-0316",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple cross-site scripting (XSS) vulnerabilities in usercp.php in MyBulletinBoard (MyBB) 1.02 allow remote attackers to inject arbitrary web script or HTML via the (1) notepad parameter in a notepad action and (2) signature parameter in an editsig action. NOTE: These are different attack vectors, and probably a different vulnerability, than CVE-2006-0218 and CVE-2006-0219."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mybb:mybb:1.0.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-26T22:03Z",
    "lastModifiedDate" : "2018-10-19T15:44Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0443",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "cheesyblog",
            "product" : {
              "product_data" : [ {
                "product_name" : "cheesyblog",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://evuln.com/vulns/49/summary.html",
          "name" : "http://evuln.com/vulns/49/summary.html",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18610",
          "name" : "18610",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/369",
          "name" : "369",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/22716",
          "name" : "22716",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/423023/100/0/threaded",
          "name" : "20060125 [eVuln] CheesyBlog XSS Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16376",
          "name" : "16376",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0326",
          "name" : "ADV-2006-0326",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24292",
          "name" : "cheesyblog-archive-xss(24292)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in archive.php in CheesyBlog 1.0 allows remote attackers to inject arbitrary web script or HTML via the (1) realname and (2) comment parameters, or (3) via a javascript URI in the url parameter, when adding a comment."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cheesyblog:cheesyblog:1.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-26T22:03Z",
    "lastModifiedDate" : "2018-10-19T15:44Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0444",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "phpclanwebsite",
            "product" : {
              "product_data" : [ {
                "product_name" : "phpclanwebsite",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.23.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18597",
          "name" : "18597",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.h4cky0u.org/advisories/HYSA-2006-002-phpclan.txt",
          "name" : "http://www.h4cky0u.org/advisories/HYSA-2006-002-phpclan.txt",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/22720",
          "name" : "22720",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/22722",
          "name" : "22722",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/423145/100/0/threaded",
          "name" : "20060125 HYSA-2006-002 Phpclanwebsite 1.23.1 Multiple Vulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16391",
          "name" : "16391",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0342",
          "name" : "ADV-2006-0342",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24355",
          "name" : "phpclanwebsite-index-sql-injection(24355)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in index.php in Phpclanwebsite (aka PCW) 1.23.1 allows remote attackers to execute arbitrary SQL commands via the (1) par parameter in the post function on the forum page and possibly the (2) poll_id parameter on the poll page.  NOTE: the poll_id vector can also allow resultant cross-site scripting (XSS) from an unquoted error message for invalid SQL syntax."
        }, {
          "lang" : "en",
          "value" : "A simple fix has been released on the Main PCW site available directly at <a href=\"http://www.phpclanwebsite.com/index.php?page=downloads&func=browselist&par=1\">http://www.phpclanwebsite.com/index.php?page=downloads&func=browselist&par=1</a>\r\nPlease download and install imediately.\r\nTech note: Filters id number (par) to contain numbers only.\r\n"
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:phpclanwebsite:phpclanwebsite:1.23.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-26T22:03Z",
    "lastModifiedDate" : "2018-10-19T15:44Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0445",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "phpclanwebsite",
            "product" : {
              "product_data" : [ {
                "product_name" : "phpclanwebsite",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.23.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.h4cky0u.org/advisories/HYSA-2006-002-phpclan.txt",
          "name" : "http://www.h4cky0u.org/advisories/HYSA-2006-002-phpclan.txt",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/22721",
          "name" : "22721",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/423145/100/0/threaded",
          "name" : "20060125 HYSA-2006-002 Phpclanwebsite 1.23.1 Multiple Vulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16391",
          "name" : "16391",
          "refsource" : "BID",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "index.php in Phpclanwebsite 1.23.1 allows remote authenticated users to obtain the installation path by specifying an invalid file name to the uploader page, as demonstrated by \"\\\", which will display the full path of uploader.php.  NOTE: this might be the result of a file inclusion vulnerability."
        }, {
          "lang" : "en",
          "value" : "Please add the following to the config.php file to avoid all such exploits.\r\n\r\nini_set('display_errors', false);\r\n"
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:phpclanwebsite:phpclanwebsite:1.23.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-26T22:03Z",
    "lastModifiedDate" : "2018-10-19T15:44Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0446",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "webwork",
            "product" : {
              "product_data" : [ {
                "product_name" : "webwork",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2-pre1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://devel.webwork.rochester.edu/twiki/bin/view/Webwork/WeBWorKRelease2pt1pt4",
          "name" : "http://devel.webwork.rochester.edu/twiki/bin/view/Webwork/WeBWorKRelease2pt1pt4",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://secunia.com/advisories/18594",
          "name" : "18594",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16371",
          "name" : "16371",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0319",
          "name" : "ADV-2006-0319",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24322",
          "name" : "webwork-unknown-command-execution(24322)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in WeBWorK 2.1.3 and 2.2-pre1 allows remote privileged attackers to execute arbitrary commands as the web server via unknown attack vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:webwork:webwork:2.1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:webwork:webwork:2.2-pre1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.5
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-27T00:03Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0447",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "e-post_corporation",
            "product" : {
              "product_data" : [ {
                "product_name" : "mail_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "enterprise_4.10",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "smtp_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "enterprise_4.10",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "spa-pro_mail_atsolomon",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.00",
                    "version_affected" : "="
                  }, {
                    "version_value" : "enterprise_4.00",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18480",
          "name" : "18480",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/secunia_research/2006-1/advisory/",
          "name" : "http://secunia.com/secunia_research/2006-1/advisory/",
          "refsource" : "MISC",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/22761",
          "name" : "22761",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/22762",
          "name" : "22762",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/22763",
          "name" : "22763",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16379",
          "name" : "16379",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0318",
          "name" : "ADV-2006-0318",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24331",
          "name" : "epost-smtp-username-bo(24331)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24333",
          "name" : "epost-pop3-username-bo(24333)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24334",
          "name" : "epost-imap-mailbox-dos(24334)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple buffer overflows in E-Post Mail Server 4.10 and SPA-PRO Mail @Solomon 4.00 allow remote attackers to execute arbitrary code via a long username to the (1) AUTH PLAIN or (2) AUTH LOGIN SMTP commands, which is not properly handled by (a) EPSTRS.EXE or (b) SPA-RS.EXE; (3) a long username in the APOP POP3 command, which is not properly handled by (c) EPSTPOP4S.EXE or (d) SPA-POP3S.EXE; (4) a long IMAP DELETE command, which is not properly handled by (e) EPSTIMAP4S.EXE or (f) SPA-IMAP4S.EXE."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:e-post_corporation:mail_server:4.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:e-post_corporation:mail_server:enterprise_4.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:e-post_corporation:smtp_server:4.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:e-post_corporation:smtp_server:enterprise_4.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:e-post_corporation:spa-pro_mail_atsolomon:4.00:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:e-post_corporation:spa-pro_mail_atsolomon:enterprise_4.00:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-27T00:03Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0448",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "e-post_corporation",
            "product" : {
              "product_data" : [ {
                "product_name" : "mail_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.05",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "spa-pro_mail_atsolomon",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.05",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18480",
          "name" : "18480",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/secunia_research/2006-1/advisory/",
          "name" : "http://secunia.com/secunia_research/2006-1/advisory/",
          "refsource" : "MISC",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/22764",
          "name" : "22764",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/22765",
          "name" : "22765",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16379",
          "name" : "16379",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0318",
          "name" : "ADV-2006-0318",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24336",
          "name" : "epost-append-copy-rename-file-creation(24336)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple directory traversal vulnerabilities in (1) EPSTIMAP4S.EXE and (2) SPA-IMAP4S.EXE in the IMAP service in E-Post Mail 4.05 and SPA-PRO Mail 4.05 allow remote attackers to (a) list arbitrary directories or cause a denial of service via the LIST command; or create arbitrary files via the (b) APPEND, (c) COPY, or (d) RENAME commands."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:e-post_corporation:mail_server:4.05:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:e-post_corporation:spa-pro_mail_atsolomon:4.05:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-27T00:03Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0449",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "e-post_corporation",
            "product" : {
              "product_data" : [ {
                "product_name" : "mail_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.05",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "spa-pro_mail_atsolomon",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.05",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18480",
          "name" : "18480",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/secunia_research/2006-1/advisory/",
          "name" : "http://secunia.com/secunia_research/2006-1/advisory/",
          "refsource" : "MISC",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/22766",
          "name" : "22766",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16379",
          "name" : "16379",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0318",
          "name" : "ADV-2006-0318",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24341",
          "name" : "epost-imap-append-dos(24341)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Early termination vulnerability in the IMAP service in E-Post Mail 4.05 and SPA-PRO Mail 4.05 allows remote attackers to cause a denial of service (infinite loop) by sending an APPEND command and disconnecting before the expected amount of data is sent."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:e-post_corporation:mail_server:4.05:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:e-post_corporation:spa-pro_mail_atsolomon:4.05:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-27T00:03Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0450",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "phpbb_group",
            "product" : {
              "product_data" : [ {
                "product_name" : "phpbb",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.6c",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.6d",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.7a",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.8a",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.16",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.17",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.18",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.19",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0_beta1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0_rc1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0_rc2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0_rc3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0_rc4",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://h4cky0u.org/viewtopic.php?t=637",
          "name" : "http://h4cky0u.org/viewtopic.php?t=637",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/368",
          "name" : "368",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.h4cky0u.org/advisories/HYSA-2006-001-phpbb.txt",
          "name" : "http://www.h4cky0u.org/advisories/HYSA-2006-001-phpbb.txt",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/423030/100/0/threaded",
          "name" : "20060125 HYSA-2006-001 phpBB 2.0.19 search.php and profile.php DOS Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24327",
          "name" : "phpbb-search-profile-dos(24327)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "phpBB 2.0.19 and earlier allows remote attackers to cause a denial of service (application crash) by (1) registering many users through profile.php or (2) using search.php to search in a certain way that confuses the database."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:phpbb_group:phpbb:2.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:phpbb_group:phpbb:2.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:phpbb_group:phpbb:2.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:phpbb_group:phpbb:2.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:phpbb_group:phpbb:2.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:phpbb_group:phpbb:2.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:phpbb_group:phpbb:2.0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:phpbb_group:phpbb:2.0.6c:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:phpbb_group:phpbb:2.0.6d:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:phpbb_group:phpbb:2.0.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:phpbb_group:phpbb:2.0.7a:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:phpbb_group:phpbb:2.0.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:phpbb_group:phpbb:2.0.8a:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:phpbb_group:phpbb:2.0.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:phpbb_group:phpbb:2.0.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:phpbb_group:phpbb:2.0.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:phpbb_group:phpbb:2.0.12:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:phpbb_group:phpbb:2.0.13:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:phpbb_group:phpbb:2.0.14:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:phpbb_group:phpbb:2.0.15:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:phpbb_group:phpbb:2.0.16:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:phpbb_group:phpbb:2.0.17:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:phpbb_group:phpbb:2.0.18:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:phpbb_group:phpbb:2.0.19:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:phpbb_group:phpbb:2.0_beta1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:phpbb_group:phpbb:2.0_rc1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:phpbb_group:phpbb:2.0_rc2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:phpbb_group:phpbb:2.0_rc3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:phpbb_group:phpbb:2.0_rc4:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-27T00:03Z",
    "lastModifiedDate" : "2018-10-19T15:44Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0451",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "redhat",
            "product" : {
              "product_data" : [ {
                "product_name" : "fedora_core",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=179135",
          "name" : "http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=179135",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18960",
          "name" : "18960",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16677",
          "name" : "16677",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24794",
          "name" : "fedora-ber-memory-leak-dos(24794)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple memory leaks in the LDAP component in Fedora Directory Server 1.0 allow remote attackers to cause a denial of service (memory consumption) via invalid BER packets that trigger an error, which might prevent memory from being freed if it was allocated during the ber_scanf call, as demonstrated using the ProtoVer LDAP test suite."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:fedora_core:1.0:*:directory_server:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-14T22:06Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0452",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "redhat",
            "product" : {
              "product_data" : [ {
                "product_name" : "fedora_core",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=179137",
          "name" : "http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=179137",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18960",
          "name" : "18960",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16677",
          "name" : "16677",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24796",
          "name" : "fedora-dn2ancestor-dos(24796)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "dn2ancestor in the LDAP component in Fedora Directory Server 1.0 allows remote attackers to cause a denial of service (CPU and memory consumption) via a ModDN operation with a DN that contains a large number of \",\" (comma) characters, which results in a large amount of recursion, as demonstrated using the ProtoVer LDAP test suite."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:fedora_core:1.0:*:directory_server:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-14T22:06Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0453",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "redhat",
            "product" : {
              "product_data" : [ {
                "product_name" : "fedora_core",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=179135",
          "name" : "http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=179135",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18960",
          "name" : "18960",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16677",
          "name" : "16677",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24795",
          "name" : "fedora-ber-bad-sequence-dos(24795)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The LDAP component in Fedora Directory Server 1.0 allow remote attackers to cause a denial of service (crash) via a certain \"bad BER sequence\" that results in a free of uninitialized memory, as demonstrated using the ProtoVer LDAP test suite."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:fedora_core:1.0:*:directory_server:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.8
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-14T22:06Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0454",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "linux",
            "product" : {
              "product_data" : [ {
                "product_name" : "linux_kernel",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.6.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.12.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.12.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.12.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.12.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.12.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.12.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.13.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.13.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.13.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.13.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.13.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.14.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.14.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.14.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.14.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.14.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.14.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.14.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.15.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.15.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-399"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.immunitysec.com/pipermail/dailydave/2006-February/002909.html",
          "name" : "[dailydave] 20060207 Fun with Linux (2.6.12 -> 2.6.15.2)",
          "refsource" : "MLIST",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://marc.info/?l=linux-kernel&m=113927617401569&w=2",
          "name" : "[linux-kernel] 20060207 Linux 2.6.15.3",
          "refsource" : "MLIST",
          "tags" : [ ]
        }, {
          "url" : "http://marc.info/?l=linux-kernel&m=113927648820694&w=2",
          "name" : "[linux-kernel] 20060207 Re: Linux 2.6.15.3",
          "refsource" : "MLIST",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18766",
          "name" : "18766",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18774",
          "name" : "18774",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18784",
          "name" : "18784",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18788",
          "name" : "18788",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18861",
          "name" : "18861",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.15.3",
          "name" : "http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.15.3",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDKSA-2006:040",
          "name" : "MDKSA-2006:040",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.novell.com/linux/security/advisories/2006_06_kernel.html",
          "name" : "SUSE-SA:2006:006",
          "refsource" : "SUSE",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.redhat.com/archives/fedora-announce-list/2006-February/msg00037.html",
          "name" : "FEDORA-2006-102",
          "refsource" : "FEDORA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/427981/100/0/threaded",
          "name" : "FLSA:157459-4",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16532",
          "name" : "16532",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.trustix.org/errata/2006/0006",
          "name" : "2006-0006",
          "refsource" : "TRUSTIX",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.ubuntu.com/usn/usn-250-1",
          "name" : "USN-250-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0464",
          "name" : "ADV-2006-0464",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24575",
          "name" : "kernel-icmp-ipoptionsecho-dos(24575)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Linux kernel before 2.6.15.3 down to 2.6.12, while constructing an ICMP response in icmp_send, does not properly handle when the ip_options_echo function in icmp.c fails, which allows remote attackers to cause a denial of service (crash) via vectors such as (1) record-route and (2) timestamp IP options with the needaddr bit set and a truncated value."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.12:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.12:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.12:rc2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.12:rc3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.12:rc4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.12:rc5:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.12:rc6:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.12.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.12.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.12.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.12.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.12.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.12.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.13:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.13:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.13:rc2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.13:rc3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.13:rc4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.13:rc5:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.13:rc6:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.13:rc7:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.13.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.13.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.13.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.13.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.13.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.14:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.14:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.14:rc2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.14:rc3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.14:rc4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.14:rc5:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.14.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.14.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.14.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.14.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.14.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.14.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.14.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.15:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.15.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.15.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-07T18:06Z",
    "lastModifiedDate" : "2018-10-19T15:44Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0455",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "gnu",
            "product" : {
              "product_data" : [ {
                "product_name" : "privacy_guard",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.3b",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "ftp://patches.sgi.com/support/free/security/advisories/20060401-01-U",
          "name" : "20060401-01-U",
          "refsource" : "SGI",
          "tags" : [ ]
        }, {
          "url" : "http://fedoranews.org/updates/FEDORA-2006-116.shtml",
          "name" : "FEDORA-2006-116",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "http://lists.gnupg.org/pipermail/gnupg-announce/2006q1/000211.html",
          "name" : "[gnupg-announce] 20060215 False positive signature verification in GnuPG",
          "refsource" : "MLIST",
          "tags" : [ ]
        }, {
          "url" : "http://marc.info/?l=gnupg-devel&m=113999098729114&w=2",
          "name" : "[gnupg-devel] 20060215 [Announce] False positive signature verification in GnuPG",
          "refsource" : "MLIST",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18845",
          "name" : "18845",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18933",
          "name" : "18933",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18934",
          "name" : "18934",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18942",
          "name" : "18942",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18955",
          "name" : "18955",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18956",
          "name" : "18956",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18968",
          "name" : "18968",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/19130",
          "name" : "19130",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/19249",
          "name" : "19249",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/19532",
          "name" : "19532",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.gentoo.org/security/en/glsa/glsa-200602-10.xml",
          "name" : "GLSA-200602-10",
          "refsource" : "GENTOO",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDKSA-2006:043",
          "name" : "MDKSA-2006:043",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.novell.com/linux/security/advisories/2006_05_sr.html",
          "name" : "SUSE-SR:2006:005",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://www.novell.com/linux/security/advisories/2006_09_gpg.html",
          "name" : "SUSE-SA:2006:009",
          "refsource" : "SUSE",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.novell.com/linux/security/advisories/2006_13_gpg.html",
          "name" : "SUSE-SA:2006:013",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://www.openpkg.org/security/OpenPKG-SA-2006.001-gnupg.html",
          "name" : "OpenPKG-SA-2006.001",
          "refsource" : "OPENPKG",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/23221",
          "name" : "23221",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2006-0266.html",
          "name" : "RHSA-2006:0266",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/425289/100/0/threaded",
          "name" : "20060215 False positive signature verification in GnuPG",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/433931/100/0/threaded",
          "name" : "FLSA-2006:185355",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16663",
          "name" : "16663",
          "refsource" : "BID",
          "tags" : [ "Exploit", "Patch" ]
        }, {
          "url" : "http://www.slackware.com/security/viewer.php?l=slackware-security&y=2006&m=slackware-security.476477",
          "name" : "SSA:2006-072-02",
          "refsource" : "SLACKWARE",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.trustix.org/errata/2006/0008",
          "name" : "2006-0008",
          "refsource" : "TRUSTIX",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/usn-252-1",
          "name" : "USN-252-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "http://www.us.debian.org/security/2006/dsa-978",
          "name" : "DSA-978",
          "refsource" : "DEBIAN",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0610",
          "name" : "ADV-2006-0610",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24744",
          "name" : "gnupg-gpgv-improper-verification(24744)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10084",
          "name" : "oval:org.mitre.oval:def:10084",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "gpgv in GnuPG before 1.4.2.1, when using unattended signature verification, returns a 0 exit code in certain cases even when the detached signature file does not carry a signature, which could cause programs that use gpgv to assume that the signature verification has succeeded.  Note: this also occurs when running the equivalent command \"gpg --verify\"."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:gnu:privacy_guard:1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:gnu:privacy_guard:1.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:gnu:privacy_guard:1.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:gnu:privacy_guard:1.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:gnu:privacy_guard:1.0.3b:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:gnu:privacy_guard:1.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:gnu:privacy_guard:1.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:gnu:privacy_guard:1.0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:gnu:privacy_guard:1.0.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:gnu:privacy_guard:1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:gnu:privacy_guard:1.2.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:gnu:privacy_guard:1.2.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:gnu:privacy_guard:1.2.2:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:gnu:privacy_guard:1.2.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:gnu:privacy_guard:1.2.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:gnu:privacy_guard:1.2.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:gnu:privacy_guard:1.2.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:gnu:privacy_guard:1.2.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:gnu:privacy_guard:1.3.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:gnu:privacy_guard:1.3.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:gnu:privacy_guard:1.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:gnu:privacy_guard:1.4.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:gnu:privacy_guard:1.4.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 4.6
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 3.9,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-15T22:06Z",
    "lastModifiedDate" : "2018-10-19T15:44Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0456",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "linux",
            "product" : {
              "product_data" : [ {
                "product_name" : "linux_kernel",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.12.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.12.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.12.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.12.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.12.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.12.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.13.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.13.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.13.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.13.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.14.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.14.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.14.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.14.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.14.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.15.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.15.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.15.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.15.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.15.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6_test9_cvs",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/20914",
          "name" : "20914",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/21465",
          "name" : "21465",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/22417",
          "name" : "22417",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://support.avaya.com/elmodocs2/security/ASA-2006-200.htm",
          "name" : "http://support.avaya.com/elmodocs2/security/ASA-2006-200.htm",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2006/dsa-1103",
          "name" : "DSA-1103",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=331c46591414f7f92b1cec048009abe89892ee79",
          "name" : "http://www.kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=331c46591414f7f92b1cec048009abe89892ee79",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commitdiff;h=331c46591414f7f92b1cec048009abe89892ee79",
          "name" : "http://www.kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commitdiff;h=331c46591414f7f92b1cec048009abe89892ee79",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.16-rc6",
          "name" : "http://www.kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.16-rc6",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.mail-archive.com/kernel-svn-changes@lists.alioth.debian.org/msg01631.html",
          "name" : "http://www.mail-archive.com/kernel-svn-changes@lists.alioth.debian.org/msg01631.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2006-0575.html",
          "name" : "RHSA-2006:0575",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/18687",
          "name" : "18687",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/2554",
          "name" : "ADV-2006-2554",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9909",
          "name" : "oval:org.mitre.oval:def:9909",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The strnlen_user function in Linux kernel before 2.6.16 on IBM S/390 can return an incorrect value, which allows local users to cause a denial of service via unknown vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.0:test1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.0:test10:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.0:test11:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.0:test2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.0:test3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.0:test4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.0:test5:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.0:test6:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.0:test7:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.0:test8:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.0:test9:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.1:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.1:rc2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.2:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.2:rc2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.2:rc3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.3:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.3:rc2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.3:rc3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.4:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.4:rc2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.4:rc3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.5:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.5:rc2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.5:rc3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.6:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.6:rc2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.6:rc3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.7:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.7:rc2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.7:rc3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.8:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.8:rc2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.8:rc3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.8:rc4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.9:2.6.20:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.9:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.9:rc2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.9:rc3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.9:rc4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.10:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.10:rc2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.10:rc3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11:rc2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11:rc3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11:rc4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11:rc5:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11.12:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.12:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.12:rc2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.12:rc3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.12:rc4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.12:rc5:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.12:rc6:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.12.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.12.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.12.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.12.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.12.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.12.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.13:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.13:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.13:rc2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.13:rc3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.13:rc4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.13:rc5:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.13:rc6:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.13:rc7:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.13.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.13.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.13.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.13.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.14:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.14:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.14:rc2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.14:rc3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.14:rc4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.14:rc5:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.14.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.14.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.14.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.14.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.14.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.15:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.15:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.15:rc3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.15:rc4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.15:rc5:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.15:rc6:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.15:rc7:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.15.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.15.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.15.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.15.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.15.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6_test9_cvs:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 2.1
        },
        "severity" : "LOW",
        "exploitabilityScore" : 3.9,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-06-27T23:05Z",
    "lastModifiedDate" : "2017-10-11T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0457",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "linux",
            "product" : {
              "product_data" : [ {
                "product_name" : "linux_kernel",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.8.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.8.1.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11_rc1_bk6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.12.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.12.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.12.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.12.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.12.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.12.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.13.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.13.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.13.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.13.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.14.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.14.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.14.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.14.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.15.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.15.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.15.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.15.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.15.5",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/19220",
          "name" : "19220",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/20398",
          "name" : "20398",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/21465",
          "name" : "21465",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/22417",
          "name" : "22417",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://support.avaya.com/elmodocs2/security/ASA-2006-200.htm",
          "name" : "http://support.avaya.com/elmodocs2/security/ASA-2006-200.htm",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDKSA-2006:059",
          "name" : "MDKSA-2006:059",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.novell.com/linux/security/advisories/2006-05-31.html",
          "name" : "SUSE-SA:2006:028",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/23894",
          "name" : "23894",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2006-0575.html",
          "name" : "RHSA-2006:0575",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/17084",
          "name" : "17084",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/25354",
          "name" : "kernel-addkey-dos(25354)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9566",
          "name" : "oval:org.mitre.oval:def:9566",
          "refsource" : "OVAL",
          "tags" : [ ]
        }, {
          "url" : "https://usn.ubuntu.com/263-1/",
          "name" : "USN-263-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Race condition in the (1) add_key, (2) request_key, and (3) keyctl functions in Linux kernel 2.6.x allows local users to cause a denial of service (crash) or read sensitive kernel memory by modifying the length of a string argument between the time that the kernel calculates the length and when it copies the data into kernel memory."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.0:test1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.0:test10:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.0:test11:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.0:test2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.0:test3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.0:test4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.0:test5:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.0:test6:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.0:test7:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.0:test8:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.0:test9:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.1:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.1:rc2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.6:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.7:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.8:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.8:rc2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.8:rc3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.8.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.8.1.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.9:2.6.20:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.10:rc2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11:rc2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11:rc3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11:rc4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11.12:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11_rc1_bk6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.12:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.12:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.12:rc4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.12:rc5:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.12.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.12.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.12.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.12.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.12.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.12.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.13:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.13:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.13:rc4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.13:rc6:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.13:rc7:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.13.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.13.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.13.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.13.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.14:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.14:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.14:rc2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.14:rc3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.14:rc4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.14.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.14.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.14.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.14.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.15:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.15:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.15:rc3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.15:rc4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.15:rc5:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.15:rc6:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.15:rc7:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.15.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.15.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.15.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.15.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.15.5:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:H/Au:N/C:C/I:N/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "HIGH",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.1
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 4.9,
        "impactScore" : 9.2,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-03-14T02:02Z",
    "lastModifiedDate" : "2018-10-03T21:35Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0458",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "irssi",
            "product" : {
              "product_data" : [ {
                "product_name" : "irssi",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.8.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8.10rc5",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/19090",
          "name" : "19090",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16913",
          "name" : "16913",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/25147",
          "name" : "irssi-dcc-accept-dos(25147)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://usn.ubuntu.com/259-1/",
          "name" : "USN-259-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The DCC ACCEPT command handler in irssi before 0.8.9+0.8.10rc5-0ubuntu4.1 in Ubuntu Linux, and possibly other distributions, allows remote attackers to cause a denial of service (application crash) via certain crafted arguments in a DCC command."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:irssi:irssi:0.8.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:irssi:irssi:0.8.10rc5:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-03-06T23:02Z",
    "lastModifiedDate" : "2018-10-03T21:35Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0459",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "will_estes_and_john_millaway",
            "product" : {
              "product_data" : [ {
                "product_name" : "flex",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.5.30",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.5.32",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://prdownloads.sourceforge.net/flex/flex-2.5.33.tar.bz2?download",
          "name" : "http://prdownloads.sourceforge.net/flex/flex-2.5.33.tar.bz2?download",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/19071",
          "name" : "19071",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/19126",
          "name" : "19126",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/19228",
          "name" : "19228",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/19424",
          "name" : "19424",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/570",
          "name" : "570",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://sourceforge.net/mailarchive/forum.php?thread_name=20060223020346.GA11231%40tabitha.home.tldz.org&forum_name=flex-announce",
          "name" : "[flex-announce] 20060222 flex 2.5.33 released",
          "refsource" : "MLIST",
          "tags" : [ ]
        }, {
          "url" : "http://www.gentoo.org/security/en/glsa/glsa-200603-07.xml",
          "name" : "GLSA-200603-07",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/23440",
          "name" : "23440",
          "refsource" : "OSVDB",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16896",
          "name" : "16896",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.us.debian.org/security/2006/dsa-1020",
          "name" : "DSA-1020",
          "refsource" : "DEBIAN",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0770",
          "name" : "ADV-2006-0770",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24995",
          "name" : "flex-bypass-security(24995)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://usn.ubuntu.com/260-1/",
          "name" : "USN-260-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "flex.skl in Will Estes and John Millaway Fast Lexical Analyzer Generator (flex) before 2.5.33 does not allocate enough memory for grammars containing (1) REJECT statements or (2) trailing context rules, which causes flex to generate code that contains a buffer overflow that might allow context-dependent attackers to execute arbitrary code."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:will_estes_and_john_millaway:flex:2.5.30:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:will_estes_and_john_millaway:flex:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "2.5.32"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-03-29T23:02Z",
    "lastModifiedDate" : "2018-10-03T21:35Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0460",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "bomberclone",
            "product" : {
              "product_data" : [ {
                "product_name" : "bomberclone",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.9.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.9.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.9.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.9.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.9.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.10.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.11.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.11.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.11.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.11.6",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18914",
          "name" : "18914",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18915",
          "name" : "18915",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/19210",
          "name" : "19210",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2006/dsa-997",
          "name" : "DSA-997",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.gentoo.org/security/en/glsa/glsa-200602-09.xml",
          "name" : "GLSA-200602-09",
          "refsource" : "GENTOO",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/23263",
          "name" : "23263",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16697",
          "name" : "16697",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0643",
          "name" : "ADV-2006-0643",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24764",
          "name" : "bomberclone-error-message-bo(24764)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple buffer overflows in BomberClone before 0.11.6.2 allow remote attackers to execute arbitrary code via long error messages."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bomberclone:bomberclone:0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bomberclone:bomberclone:0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bomberclone:bomberclone:0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bomberclone:bomberclone:0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bomberclone:bomberclone:0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bomberclone:bomberclone:0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bomberclone:bomberclone:0.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bomberclone:bomberclone:0.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bomberclone:bomberclone:0.9.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bomberclone:bomberclone:0.9.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bomberclone:bomberclone:0.9.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bomberclone:bomberclone:0.9.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bomberclone:bomberclone:0.9.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bomberclone:bomberclone:0.10.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bomberclone:bomberclone:0.11.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bomberclone:bomberclone:0.11.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bomberclone:bomberclone:0.11.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bomberclone:bomberclone:0.11.6:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-17T01:02Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0461",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "pmachine",
            "product" : {
              "product_data" : [ {
                "product_name" : "expressionengine",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.4.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://evuln.com/vulns/48/summary.html",
          "name" : "http://evuln.com/vulns/48/summary.html",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18602",
          "name" : "18602",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/372",
          "name" : "372",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/423068/100/0/threaded",
          "name" : "20060125 [eVuln] ExpressionEngine 'Referer' XSS Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16377",
          "name" : "16377",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0325",
          "name" : "ADV-2006-0325",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24296",
          "name" : "expressionengine-coreinput-xss(24296)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in core.input.php in ExpressionEngine 1.4.1 allows remote attackers to inject arbitrary web script or HTML via HTTP_REFERER (referer)."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pmachine:expressionengine:1.4.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-27T23:03Z",
    "lastModifiedDate" : "2018-10-19T15:44Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0462",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "andonet",
            "product" : {
              "product_data" : [ {
                "product_name" : "andonet_blog",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2004.09.02",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://evuln.com/vulns/50/summary.html",
          "name" : "http://evuln.com/vulns/50/summary.html",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18633",
          "name" : "18633",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/377",
          "name" : "377",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/22755",
          "name" : "22755",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/423162",
          "name" : "20060126 [eVuln] AndoNET Blog SQL Injection Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16393",
          "name" : "16393",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0327",
          "name" : "ADV-2006-0327",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24309",
          "name" : "andonetblog-index-sql-injection(24309)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in comentarios.php in AndoNET Blog 2004.09.02 allows remote attackers to execute arbitrary SQL commands via the entrada parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:andonet:andonet_blog:2004.09.02:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-27T23:03Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0463",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ideosoft_design",
            "product" : {
              "product_data" : [ {
                "product_name" : "ideocontent_manager",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/ref/22/22712-ideocontent.txt",
          "name" : "http://osvdb.org/ref/22/22712-ideocontent.txt",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.osvdb.org/22712",
          "name" : "22712",
          "refsource" : "OSVDB",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.osvdb.org/22713",
          "name" : "22713",
          "refsource" : "OSVDB",
          "tags" : [ "Exploit" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in IdeoContent Manager allows remote attackers to inject arbitrary web script or HTML via the (1) goto_id parameter to index.php or (2) page parameter to news_full.php."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ideosoft_design:ideocontent_manager:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-27T23:03Z",
    "lastModifiedDate" : "2008-09-05T20:59Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0464",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ideosoft_design",
            "product" : {
              "product_data" : [ {
                "product_name" : "ideocontent_manager",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/ref/22/22712-ideocontent.txt",
          "name" : "http://osvdb.org/ref/22/22712-ideocontent.txt",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.osvdb.org/22714",
          "name" : "22714",
          "refsource" : "OSVDB",
          "tags" : [ "Exploit" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple SQL injection vulnerabilities in index.php in IdeoContent Manager allow remote attackers to execute arbitrary SQL commands via the (1) goto_id or (2) mid parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ideosoft_design:ideocontent_manager:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-27T23:03Z",
    "lastModifiedDate" : "2008-09-05T20:59Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0465",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "active121",
            "product" : {
              "product_data" : [ {
                "product_name" : "site_manager",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/ref/22/22715-active121.txt",
          "name" : "http://osvdb.org/ref/22/22715-active121.txt",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.osvdb.org/22715",
          "name" : "22715",
          "refsource" : "OSVDB",
          "tags" : [ "Exploit" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in risultati_ricerca.php in active121 Site Manager allows remote attackers to inject arbitrary web script or HTML via the cerca parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:active121:site_manager:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-27T23:03Z",
    "lastModifiedDate" : "2008-09-05T20:59Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0466",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "goldstag",
            "product" : {
              "product_data" : [ {
                "product_name" : "goldstag_content_management_system",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/ref/22/22711-goldstag.txt",
          "name" : "http://osvdb.org/ref/22/22711-goldstag.txt",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.osvdb.org/22711",
          "name" : "22711",
          "refsource" : "OSVDB",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/25198",
          "name" : "goldstag-search-xss(25198)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in search.asp in Goldstag Content Management System allows remote attackers to inject arbitrary web script or HTML via the text parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:goldstag:goldstag_content_management_system:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-27T23:03Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0467",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "pioneers",
            "product" : {
              "product_data" : [ {
                "product_name" : "pioneers",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.9.49",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=350237",
          "name" : "http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=350237",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18647",
          "name" : "18647",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18692",
          "name" : "18692",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.debian.org/security/2006/dsa-964",
          "name" : "DSA-964",
          "refsource" : "DEBIAN",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16429",
          "name" : "16429",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0376",
          "name" : "ADV-2006-0376",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24383",
          "name" : "pioneers-chat-message-dos(24383)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in Pioneers (formerly gnocatan) before 0.9.49 allows remote attackers to cause a denial of service (application crash) via long chat messages."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pioneers:pioneers:0.9.49:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-31T02:03Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0468",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "stalker",
            "product" : {
              "product_data" : [ {
                "product_name" : "communigate_pro",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0c1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0c2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0c3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0c4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0c5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0c6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0c7",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18640",
          "name" : "18640",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.gleg.net/advisory_cg.shtml",
          "name" : "http://www.gleg.net/advisory_cg.shtml",
          "refsource" : "MISC",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/423364/100/0/threaded",
          "name" : "20060128 Multiple vulnerabilities in CommuniGate Pro Server",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16407",
          "name" : "16407",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.stalker.com/CommuniGatePro/History.html",
          "name" : "http://www.stalker.com/CommuniGatePro/History.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0364",
          "name" : "ADV-2006-0364",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24409",
          "name" : "communigate-ldap-bo(24409)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "CommuniGate Pro Core Server before 5.0.7 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via LDAP messages with negative BER lengths, and possibly other vectors, as demonstrated by the ProtoVer LDAP test suite."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:stalker:communigate_pro:5.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:stalker:communigate_pro:5.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:stalker:communigate_pro:5.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:stalker:communigate_pro:5.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:stalker:communigate_pro:5.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:stalker:communigate_pro:5.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:stalker:communigate_pro:5.0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:stalker:communigate_pro:5.0c1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:stalker:communigate_pro:5.0c2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:stalker:communigate_pro:5.0c3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:stalker:communigate_pro:5.0c4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:stalker:communigate_pro:5.0c5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:stalker:communigate_pro:5.0c6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:stalker:communigate_pro:5.0c7:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-30T18:03Z",
    "lastModifiedDate" : "2018-10-19T15:44Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0469",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "uebimiau",
            "product" : {
              "product_data" : [ {
                "product_name" : "uebimiau",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.7.9",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18655",
          "name" : "18655",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/387",
          "name" : "387",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/423437/100/0/threaded",
          "name" : "20060129 UebiMiau Webmail System Security Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16413",
          "name" : "16413",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.uebimiau.org/news.php",
          "name" : "http://www.uebimiau.org/news.php",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0388",
          "name" : "ADV-2006-0388",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24375",
          "name" : "uebimiau-html-xss(24375)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in UebiMiau 2.7.9, and possibly earlier versions, allows remote attackers to inject arbitrary web script or HTML via a javascript: URI in the SRC attribute of an IMG tag."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:uebimiau:uebimiau:2.7.9:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2006-01-30T18:03Z",
    "lastModifiedDate" : "2018-10-19T15:44Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0470",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "mybulletinboard",
            "product" : {
              "product_data" : [ {
                "product_name" : "mybulletinboard",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0_final",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0_pr2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0_preview_release_2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0_rc2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0_rc4",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://community.mybboard.net/attachment.php?aid=2181",
          "name" : "http://community.mybboard.net/attachment.php?aid=2181",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://community.mybboard.net/showthread.php?tid=6418",
          "name" : "http://community.mybboard.net/showthread.php?tid=6418",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://seclists.org/lists/bugtraq/2006/Jan/0414.html",
          "name" : "20060125 MyBB 1.0.2 XSS attack in search.php redirection",
          "refsource" : "BUGTRAQ",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18617",
          "name" : "18617",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/374",
          "name" : "374",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/22750",
          "name" : "22750",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16387",
          "name" : "16387",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0350",
          "name" : "ADV-2006-0350",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24466",
          "name" : "mybb-search-xss(24466)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in search.php in MyBulletinBoard (MyBB) 1.02 allows remote attackers to inject arbitrary web script or HTML via the (1) sortby and (2) sortordr parameters, which are not properly handled in a redirection."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mybulletinboard:mybulletinboard:1.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mybulletinboard:mybulletinboard:1.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mybulletinboard:mybulletinboard:1.0_final:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mybulletinboard:mybulletinboard:1.0_pr2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mybulletinboard:mybulletinboard:1.0_preview_release_2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mybulletinboard:mybulletinboard:1.0_rc2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mybulletinboard:mybulletinboard:1.0_rc4:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-31T11:03Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0471",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "my_little_homepage",
            "product" : {
              "product_data" : [ {
                "product_name" : "my_little_forum",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2004-04-20",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://attrition.org/pipermail/vim/2006-January/000520.html",
          "name" : "20060130 My Little Homepage - source verify of different products",
          "refsource" : "VIM",
          "tags" : [ ]
        }, {
          "url" : "http://evuln.com/vulns/51/",
          "name" : "http://evuln.com/vulns/51/",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://evuln.com/vulns/51/summary.html",
          "name" : "http://evuln.com/vulns/51/summary.html",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18628",
          "name" : "18628",
          "refsource" : "SECUNIA",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/22856",
          "name" : "22856",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/423167/100/0/threaded",
          "name" : "20060126 [eVuln] \"my little homepage\" products [link] BBCode XSS Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16395",
          "name" : "16395",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0349",
          "name" : "ADV-2006-0349",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24310",
          "name" : "mylittlehomepage-link-tag-xss(24310)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in the bbcode function in functions.php in my little homepage my little forum, as last modified in June 2005, allows remote attackers to inject arbitrary Javascript via a javascript URI in BBcode link tags."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:my_little_homepage:my_little_forum:2004-04-20:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-31T11:03Z",
    "lastModifiedDate" : "2018-10-19T15:44Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0472",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "my_little_homepage",
            "product" : {
              "product_data" : [ {
                "product_name" : "my_little_guestbook",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2004-04-20",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://attrition.org/pipermail/vim/2006-January/000520.html",
          "name" : "20060130 My Little Homepage - source verify of different products",
          "refsource" : "VIM",
          "tags" : [ ]
        }, {
          "url" : "http://evuln.com/vulns/51/",
          "name" : "http://evuln.com/vulns/51/",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://evuln.com/vulns/51/summary.html",
          "name" : "http://evuln.com/vulns/51/summary.html",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18628",
          "name" : "18628",
          "refsource" : "SECUNIA",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/22855",
          "name" : "22855",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/423167/100/0/threaded",
          "name" : "20060126 [eVuln] \"my little homepage\" products [link] BBCode XSS Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16395",
          "name" : "16395",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0349",
          "name" : "ADV-2006-0349",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24310",
          "name" : "mylittlehomepage-link-tag-xss(24310)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in guestbook.php in my little homepage my little guestbook, as last modified in March 2004, allows remote attackers to inject arbitrary Javascript via a javascript URI in BBcode link tags."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:my_little_homepage:my_little_guestbook:2004-04-20:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-31T11:03Z",
    "lastModifiedDate" : "2018-10-19T15:44Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0473",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "my_little_homepage",
            "product" : {
              "product_data" : [ {
                "product_name" : "my_little_weblog",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2004-04-20",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://attrition.org/pipermail/vim/2006-January/000520.html",
          "name" : "20060130 My Little Homepage - source verify of different products",
          "refsource" : "VIM",
          "tags" : [ ]
        }, {
          "url" : "http://evuln.com/vulns/51/",
          "name" : "http://evuln.com/vulns/51/",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://evuln.com/vulns/51/summary.html",
          "name" : "http://evuln.com/vulns/51/summary.html",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18628",
          "name" : "18628",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/378",
          "name" : "378",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/22753",
          "name" : "22753",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/423167/100/0/threaded",
          "name" : "20060126 [eVuln] \"my little homepage\" products [link] BBCode XSS Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16395",
          "name" : "16395",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0349",
          "name" : "ADV-2006-0349",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24310",
          "name" : "mylittlehomepage-link-tag-xss(24310)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in the bbcode function in weblog.php in my little homepage my little weblog, as last modified in April 2004, allows remote attackers to inject arbitrary Javascript via a javascript URI in BBcode link tags."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:my_little_homepage:my_little_weblog:2004-04-20:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-31T11:03Z",
    "lastModifiedDate" : "2018-10-19T15:45Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0474",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "shareaza",
            "product" : {
              "product_data" : [ {
                "product_name" : "shareaza",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.2.1.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://archives.neohapsis.com/archives/fulldisclosure/2006-01/0887.html",
          "name" : "20060126 Shareaza Remote Vulnerability",
          "refsource" : "FULLDISC",
          "tags" : [ ]
        }, {
          "url" : "http://cvs.sourceforge.net/viewcvs.py/shareaza/shareaza/BTPacket.cpp?r1=1.5&r2=1.5.4.1",
          "name" : "http://cvs.sourceforge.net/viewcvs.py/shareaza/shareaza/BTPacket.cpp?r1=1.5&r2=1.5.4.1",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://cvs.sourceforge.net/viewcvs.py/shareaza/shareaza/EDPacket.cpp?r1=1.15&r2=1.15.2.1",
          "name" : "http://cvs.sourceforge.net/viewcvs.py/shareaza/shareaza/EDPacket.cpp?r1=1.15&r2=1.15.2.1",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/382",
          "name" : "382",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.hustlelabs.com/shareaza_advisory.pdf",
          "name" : "http://www.hustlelabs.com/shareaza_advisory.pdf",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/423293/100/0/threaded",
          "name" : "20060127 Shareaza P2P Remote Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16399",
          "name" : "16399",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24342",
          "name" : "shareaza-btpacket-bo(24342)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24343",
          "name" : "shareaza-cedpacket-bo(24343)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24344",
          "name" : "shareaza-cpacket-bo(24344)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple integer overflows in Shareaza 2.2.1.0 allow remote attackers to execute arbitrary code via (1) a large packet length field, which causes an overflow in the ReadBuffer function in (a) BTPacket.cpp and (b) EDPacket.cpp, or (2) a large packet, which causes a heap-based overflow in the Write function in (c) Packet.h."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:shareaza:shareaza:2.2.1.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-31T11:03Z",
    "lastModifiedDate" : "2018-10-19T15:45Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0475",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "theworldsend.net",
            "product" : {
              "product_data" : [ {
                "product_name" : "php-ping",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18645",
          "name" : "18645",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.kapda.ir/advisory-231.html",
          "name" : "http://www.kapda.ir/advisory-231.html",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0368",
          "name" : "ADV-2006-0368",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24382",
          "name" : "phpping-negative-count-dos(24382)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "PHP-Ping 1.3 does not properly validate ping counts, which allows remote attackers to cause a denial of service (ping flood) via a negative count parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:theworldsend.net:php-ping:1.3:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-31T11:03Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0476",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "nullsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "winamp",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.12",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18649",
          "name" : "18649",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/386",
          "name" : "386",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/398",
          "name" : "398",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1015552",
          "name" : "1015552",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.heise.de/newsticker/meldung/68981",
          "name" : "http://www.heise.de/newsticker/meldung/68981",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/604745",
          "name" : "VU#604745",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.osvdb.org/22789",
          "name" : "22789",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/423436/100/0/threaded",
          "name" : "20060130 Winamp 5.12 - 0day exploit - code execution through playlist",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/423548/100/0/threaded",
          "name" : "20060131 Re: Re: Winamp 5.12 - 0day exploit - code execution through playlist",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16410",
          "name" : "16410",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA06-032A.html",
          "name" : "TA06-032A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0361",
          "name" : "ADV-2006-0361",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.winamp.com/player/version_history.php",
          "name" : "http://www.winamp.com/player/version_history.php",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24361",
          "name" : "winamp-playlist-filename-bo(24361)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1402",
          "name" : "oval:org.mitre.oval:def:1402",
          "refsource" : "OVAL",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/3422",
          "name" : "3422",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Buffer overflow in Nullsoft Winamp 5.12 allows remote attackers to execute arbitrary code via a playlist (pls) file with a long file name (File1 field)."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:nullsoft:winamp:5.12:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:H/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "HIGH",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.6
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 4.9,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2006-01-31T11:03Z",
    "lastModifiedDate" : "2018-10-19T15:45Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0477",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "git",
            "product" : {
              "product_data" : [ {
                "product_name" : "git",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.0b",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.4",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lwn.net/Articles/169623/",
          "name" : "http://lwn.net/Articles/169623/",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://secunia.com/advisories/18643",
          "name" : "18643",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16417",
          "name" : "16417",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0367",
          "name" : "ADV-2006-0367",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24360",
          "name" : "git-gitcheckoutindex-bo(24360)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Buffer overflow in git-checkout-index in GIT before 1.1.5 allows remote attackers to execute arbitrary code via an index file with a long symbolic link."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:git:git:1.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:git:git:1.0.0b:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:git:git:1.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:git:git:1.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:git:git:1.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:git:git:1.0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:git:git:1.0.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:git:git:1.0.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:git:git:1.1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:git:git:1.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:git:git:1.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:git:git:1.1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:git:git:1.1.4:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-31T11:03Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0478",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "cre_loaded",
            "product" : {
              "product_data" : [ {
                "product_name" : "cre_loaded",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.15",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18648",
          "name" : "18648",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.attrition.org/pipermail/vim/2006-February/000527.html",
          "name" : "20060203 vendor ack/fix: 22793: CRE Loaded files.php Unauthenticated Arbitrary File Upload (fwd)",
          "refsource" : "VIM",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/22793",
          "name" : "22793",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16415",
          "name" : "16415",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0373",
          "name" : "ADV-2006-0373",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24377",
          "name" : "creloaded-files-auth-bypass(24377)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "CRE Loaded 6.15 allows remote attackers to perform privileged actions, including uploading and creating arbitrary files, via a direct request to files.php.  NOTE: the vendor states \"The initial announcement of this risk was made on our website... and it included a patch which will close the vulnerability on all known 6.0x and 6.1x releases.  We strongly encourage users of CRE Loaded 6.x, osCMax, and other users of osCommerce who have installed HTMLArea based WYSIWYG editors and Admin Access with Levels to modify thier installations at the earliest possible moment.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cre_loaded:cre_loaded:6.15:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-31T11:03Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0479",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "pmwiki",
            "product" : {
              "product_data" : [ {
                "product_name" : "pmwiki",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.1_beta_20",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://archives.neohapsis.com/archives/fulldisclosure/2006-01/0931.html",
          "name" : "20060128 PmWiki Multiple Vulnerabilities",
          "refsource" : "FULLDISC",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18634",
          "name" : "18634",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1015550",
          "name" : "1015550",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16421",
          "name" : "16421",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.ush.it/2006/01/24/pmwiki-multiple-vulnerabilities/",
          "name" : "http://www.ush.it/2006/01/24/pmwiki-multiple-vulnerabilities/",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0375",
          "name" : "ADV-2006-0375",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24366",
          "name" : "pmwiki-path-disclosure(24366)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24367",
          "name" : "pmwiki-file-include(24367)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24368",
          "name" : "pmwiki-multiple-xss(24368)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "pmwiki.php in PmWiki 2.1 beta 20, with register_globals enabled, allows remote attackers to bypass protection mechanisms that deregister global variables by setting both a GPC variable and a GLOBALS[] variable with the same name, which causes PmWiki to unset the GLOBALS[] variable but not the GPC variable, which creates resultant vulnerabilities such as remote file inclusion and cross-site scripting (XSS)."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pmwiki:pmwiki:2.1_beta_20:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-31T11:03Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0480",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "spaiz",
            "product" : {
              "product_data" : [ {
                "product_name" : "spaiz-nuke_cms",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18672",
          "name" : "18672",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/384",
          "name" : "384",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/423451/100/0/threaded",
          "name" : "20060129 sPaiz-Nuke Cross-Site Scripting Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16412",
          "name" : "16412",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0386",
          "name" : "ADV-2006-0386",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24389",
          "name" : "spaiznuke-modules-xss(24389)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in the Articles module in sPaiz-Nuke allows remote attackers to inject arbitrary web script or HTML via the query parameter in the search file."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:spaiz:spaiz-nuke_cms:0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-31T11:03Z",
    "lastModifiedDate" : "2018-10-19T15:45Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0481",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "greg_roelofs",
            "product" : {
              "product_data" : [ {
                "product_name" : "libpng",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.2.7",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "ftp://ftp.simplesystems.org/pub/libpng/png/src/libpng-1.2.8-README.txt",
          "name" : "ftp://ftp.simplesystems.org/pub/libpng/png/src/libpng-1.2.8-README.txt",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18654",
          "name" : "18654",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18863",
          "name" : "18863",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/33137",
          "name" : "33137",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://security.gentoo.org/glsa/glsa-200812-15.xml",
          "name" : "GLSA-200812-15",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1015615",
          "name" : "1015615",
          "refsource" : "SECTRACK",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://securitytracker.com/id?1015617",
          "name" : "1015617",
          "refsource" : "SECTRACK",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2006-0205.html",
          "name" : "RHSA-2006:0205",
          "refsource" : "REDHAT",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16626",
          "name" : "16626",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0393",
          "name" : "ADV-2006-0393",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=179455",
          "name" : "https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=179455",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24396",
          "name" : "libpng-pngsetstripalpha-bo(24396)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10780",
          "name" : "oval:org.mitre.oval:def:10780",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Heap-based buffer overflow in the alpha strip capability in libpng 1.2.7 allows context-dependent attackers to cause a denial of service (crash) when the png_do_strip_filler function is used to strip alpha channels out of the image."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:greg_roelofs:libpng:1.2.7:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-31T18:03Z",
    "lastModifiedDate" : "2017-10-11T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0482",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "linux",
            "product" : {
              "product_data" : [ {
                "product_name" : "linux_kernel",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.8.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.8.1.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11_rc1_bk6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.12.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.12.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.12.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.12.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.12.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.12.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.13.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.13.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.13.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.13.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.14.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.14.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.14.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.14.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6_test9_cvs",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.debian.org/debian-sparc/2006/01/msg00129.html",
          "name" : "[debian-sparc] 20060128 `date -s' on sparc64",
          "refsource" : "MLIST",
          "tags" : [ ]
        }, {
          "url" : "http://marc.info/?l=linux-sparc&m=113861010514065&w=2",
          "name" : "[linux-sparc] 20060130 Attempts to set date with 'date -s' hang the machine",
          "refsource" : "MLIST",
          "tags" : [ ]
        }, {
          "url" : "http://marc.info/?l=linux-sparc&m=113861287813463&w=2",
          "name" : "[linux-sparc] 20060130 Re: Attempts to set date with 'date -s' hang the machine",
          "refsource" : "MLIST",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/19374",
          "name" : "19374",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2006/dsa-1017",
          "name" : "DSA-1017",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/17216",
          "name" : "17216",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0418",
          "name" : "ADV-2006-0418",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24475",
          "name" : "kernel-date-s-dos(24475)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Linux kernel 2.6.15.1 and earlier, when running on SPARC architectures, allows local users to cause a denial of service (hang) via a \"date -s\" command, which causes invalid sign extended arguments to be provided to the get_compat_timespec function call."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.0:*:64-bit_x86:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.0:*:itanium_ia64_montecito:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.0:test1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.0:test10:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.0:test11:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.0:test2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.0:test3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.0:test4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.0:test5:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.0:test6:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.0:test7:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.0:test8:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.0:test9:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.1:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.1:rc2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.6:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.7:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.8:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.8:rc2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.8:rc3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.8.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.8.1.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.8.1.5:*:386:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.8.1.5:*:686:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.8.1.5:*:686_smp:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.8.1.5:*:amd64:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.8.1.5:*:amd64_k8:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.8.1.5:*:amd64_k8_smp:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.8.1.5:*:amd64_xeon:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.8.1.5:*:k7:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.8.1.5:*:k7_smp:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.8.1.5:*:power3:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.8.1.5:*:power3_smp:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.8.1.5:*:power4:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.8.1.5:*:power4_smp:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.8.1.5:*:powerpc:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.8.1.5:*:powerpc_smp:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.9:2.6.20:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.10:rc2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11:rc2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11:rc3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11:rc4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11.12:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11_rc1_bk6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.12:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.12:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.12:rc4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.12:rc5:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.12.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.12.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.12.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.12.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.12.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.12.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.13:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.13:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.13:rc4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.13:rc6:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.13:rc7:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.13.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.13.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.13.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.13.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.14:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.14:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.14:rc2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.14:rc3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.14:rc4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.14.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.14.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.14.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.14.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.15:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.15:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.15:rc3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.15:rc4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.15:rc5:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.15:rc6:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.15:rc7:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6_test9_cvs:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 2.1
        },
        "severity" : "LOW",
        "exploitabilityScore" : 3.9,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-31T19:03Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0483",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "cisco",
            "product" : {
              "product_data" : [ {
                "product_name" : "vpn_3000_concentrator_series_software",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.7(rel)",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.7.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.7.1.f",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.7.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.7.2.a",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "vpn_3030_concentator",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.7(rel)",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.7.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.7.1.f",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.7.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.7.2.a",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18629",
          "name" : "18629",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/375",
          "name" : "375",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1015546",
          "name" : "1015546",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.cisco.com/warp/public/707/cisco-sa-20060126-vpn.shtml",
          "name" : "20060126 Cisco VPN 3000 Concentrator Vulnerable to Crafted HTTP Attack",
          "refsource" : "CISCO",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/22754",
          "name" : "22754",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16394",
          "name" : "16394",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0346",
          "name" : "ADV-2006-0346",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24330",
          "name" : "cisco-vpn-http-dos(24330)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cisco VPN 3000 series concentrators running software 4.7.0 through 4.7.2.A allow remote attackers to cause a denial of service (device reload or user disconnect) via a crafted HTTP packet."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:vpn_3000_concentrator_series_software:4.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:vpn_3000_concentrator_series_software:4.7\\(rel\\):*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:vpn_3000_concentrator_series_software:4.7.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:vpn_3000_concentrator_series_software:4.7.1.f:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:vpn_3000_concentrator_series_software:4.7.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:vpn_3000_concentrator_series_software:4.7.2.a:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:vpn_3030_concentator:4.7\\(rel\\):*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:vpn_3030_concentator:4.7.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:vpn_3030_concentator:4.7.1.f:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:vpn_3030_concentator:4.7.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:vpn_3030_concentator:4.7.2.a:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.8
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-31T20:03Z",
    "lastModifiedDate" : "2018-10-30T16:26Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0484",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "elido",
            "product" : {
              "product_data" : [ {
                "product_name" : "face_control",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://securityreason.com/securityalert/376",
          "name" : "376",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1015547",
          "name" : "1015547",
          "refsource" : "SECTRACK",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.hackerscenter.com/archive/view.asp?id=22236",
          "name" : "http://www.hackerscenter.com/archive/view.asp?id=22236",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/423155/100/0/threaded",
          "name" : "20060126 [HSC] Multiple transversal bug in vis",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16401",
          "name" : "16401",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24374",
          "name" : "facecontrol-vis-directory-traversal(24374)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Directory traversal vulnerability in Vis.pl, as part of the FACE CONTROL product, allows remote attackers to read arbitrary files via a .. (dot dot) in any parameter that opens a file, such as (1) s or (2) p."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:elido:face_control:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-01-31T20:03Z",
    "lastModifiedDate" : "2018-10-19T15:45Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0485",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "cisco",
            "product" : {
              "product_data" : [ {
                "product_name" : "ios",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "12.0t",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.0xh",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.0xk",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.0xl",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.0xn",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.0xr",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1aa",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1e",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1ec",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1ez",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1ga",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1gb",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1t",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1xa",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1xe",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1xh",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1xi",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1xj",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1xl",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1xm",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1xp",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1xq",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1xs",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1xt",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1xu",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1xv",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1xw",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1xy",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1xz",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1ya",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1yb",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1yd",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1ye",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1yf",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1yh",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1yi",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2b",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2bw",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2by",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2dd",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2dx",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2mx",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2n",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2s",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2su",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2sw",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2sxb",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2sxd",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2sxe",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2sz",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2xa",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2xb",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2xc",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2xd",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2xg",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2xh",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2xj",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2xk",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2xl",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2xm",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2xq",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2xs",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2xt",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2xu",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2xv",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2xw",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2yb",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2yc",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2yd",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2ye",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2yh",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2yk",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2yl",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2ym",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2yn",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2yt",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2yu",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2yw",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2yx",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2yy",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2yz",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2zb",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2zc",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2zd",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2ze",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2zf",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2zh",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2zj",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2zl",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2zn",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2zp",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3(11)yk2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3(11)yl",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3b",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3t",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3xa",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3xb",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3xd",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3xe",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3xf",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3xg",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3xh",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3xi",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3xj",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3xk",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3xm",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3xq",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3xr",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3xw",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3xy",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3ya",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3yb",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3yf",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3yg",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3yh",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3yi",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3yj",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3yk",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3ym",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3yq",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3ys",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3yt",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3yu",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3yx",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.4mr",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.4t",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18613",
          "name" : "18613",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1015543",
          "name" : "1015543",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.cisco.com/warp/public/707/cisco-response-20060125-aaatcl.shtml",
          "name" : "20060125 Response to AAA Command Authorization by-pass",
          "refsource" : "CISCO",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/34892",
          "name" : "34892",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16383",
          "name" : "16383",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0337",
          "name" : "ADV-2006-0337",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24308",
          "name" : "cisco-aaa-tcl-auth-bypass(24308)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5836",
          "name" : "oval:org.mitre.oval:def:5836",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The TCL shell in Cisco IOS 12.2(14)S before 12.2(14)S16, 12.2(18)S before 12.2(18)S11, and certain other releases before 25 January 2006 does not perform Authentication, Authorization, and Accounting (AAA) command authorization checks, which may allow local users to execute IOS EXEC commands that were prohibited via the AAA configuration, aka Bug ID CSCeh73049."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.0t:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.0xh:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.0xk:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.0xl:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.0xn:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.0xr:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.1aa:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.1e:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.1ec:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.1ez:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.1ga:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.1gb:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.1t:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.1xa:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.1xe:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.1xh:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.1xi:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.1xj:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.1xl:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.1xm:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.1xp:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.1xq:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.1xs:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.1xt:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.1xu:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.1xv:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.1xw:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.1xy:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.1xz:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.1ya:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.1yb:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.1yd:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.1ye:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.1yf:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.1yh:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.1yi:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.2b:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.2bw:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.2by:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.2dd:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.2dx:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.2mx:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.2n:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.2s:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.2su:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.2sw:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.2sxb:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.2sxd:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.2sxe:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.2sz:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.2xa:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.2xb:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.2xc:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.2xd:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.2xg:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.2xh:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.2xj:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.2xk:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.2xl:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.2xm:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.2xq:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.2xs:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.2xt:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.2xu:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.2xv:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.2xw:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.2yb:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.2yc:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.2yd:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.2ye:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.2yh:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.2yk:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.2yl:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.2ym:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.2yn:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.2yt:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.2yu:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.2yw:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.2yx:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.2yy:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.2yz:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.2zb:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.2zc:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.2zd:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.2ze:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.2zf:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.2zh:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.2zj:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.2zl:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.2zn:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.2zp:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.3\\(11\\)yk2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.3\\(11\\)yl:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.3b:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.3t:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.3xa:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.3xb:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.3xd:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.3xe:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.3xf:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.3xg:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.3xh:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.3xi:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.3xj:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.3xk:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.3xm:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.3xq:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.3xr:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.3xw:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.3xy:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.3ya:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.3yb:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.3yf:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.3yg:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.3yh:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.3yi:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.3yj:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.3yk:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.3ym:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.3yq:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.3ys:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.3yt:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.3yu:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.3yx:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.4mr:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.4t:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 4.6
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 3.9,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-01T02:02Z",
    "lastModifiedDate" : "2017-10-11T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0486",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "cisco",
            "product" : {
              "product_data" : [ {
                "product_name" : "ios",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "12.2(25)s",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3t",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.4",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18613",
          "name" : "18613",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1015543",
          "name" : "1015543",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.cisco.com/warp/public/707/cisco-response-20060125-aaatcl.shtml",
          "name" : "20060125 Response to AAA Command Authorization by-pass",
          "refsource" : "CISCO",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/22723",
          "name" : "22723",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24308",
          "name" : "cisco-aaa-tcl-auth-bypass(24308)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4905",
          "name" : "oval:org.mitre.oval:def:4905",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Certain Cisco IOS releases in 12.2S based trains with maintenance release number 25 and later, 12.3T based trains, and 12.4 based trains reuse a Tcl Shell process across login sessions of different local users on the same terminal if the first user does not use tclquit before exiting, which may cause subsequent local users to execute unintended commands or bypass AAA command authorization checks, aka Bug ID CSCef77770."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.2\\(25\\)s:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.3t:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:cisco:ios:12.4:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 4.6
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 3.9,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-01T02:02Z",
    "lastModifiedDate" : "2017-10-11T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0487",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "tumbleweed",
            "product" : {
              "product_data" : [ {
                "product_name" : "mailgate_email_firewall",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/archive/1/422591/100/0/threaded",
          "name" : "20060121 Tumbleweed EMF 6.x Processing Issues",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple unspecified vulnerabilities in Tumbleweed MailGate Email Firewall (EMF) 6.x allow remote attackers to (1) trigger temporarily incorrect processing of an e-mail message under \"extremely heavy loads\" and (2) cause an \"increased number of missed spam\" during \"spam outbreaks.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tumbleweed:mailgate_email_firewall:6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tumbleweed:mailgate_email_firewall:6.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tumbleweed:mailgate_email_firewall:6.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-01T02:02Z",
    "lastModifiedDate" : "2018-10-19T15:45Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0488",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "windows_2000",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_2003_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "r2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_xp",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/archive/1/423169/100/0/threaded",
          "name" : "20060124 Windows mem leakage",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24471",
          "name" : "windows-vdm-obtain-information(24471)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The VDM (Virtual DOS Machine) emulation environment for MS-DOS applications in Windows 2000, Windows XP SP2, and Windows Server 2003 allows local users to read the first megabyte of memory and possibly obtain sensitive information, as demonstrated by dumper.asm."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2000:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_2003_server:r2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_xp:*:sp2:tablet_pc:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 2.1
        },
        "severity" : "LOW",
        "exploitabilityScore" : 3.9,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-01T02:02Z",
    "lastModifiedDate" : "2018-10-19T15:45Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0489",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "khaled_mardam-bey",
            "product" : {
              "product_data" : [ {
                "product_name" : "mirc",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.16",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://securityreason.com/securityalert/383",
          "name" : "383",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://trout.snt.utwente.nl/ubbthreads/showflat.php?Cat=0&Board=bugreports&Number=118751",
          "name" : "http://trout.snt.utwente.nl/ubbthreads/showflat.php?Cat=0&Board=bugreports&Number=118751",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/22942",
          "name" : "22942",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securiteam.com/windowsntfocus/5IP080AHPQ.html",
          "name" : "http://www.securiteam.com/windowsntfocus/5IP080AHPQ.html",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/423192/100/0/threaded",
          "name" : "20060124 Buffer Overflow /Font on mIRC",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/423758/100/0/threaded",
          "name" : "20060201 Re: Buffer Overflow /Font on mIRC",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "** DISPUTED ** Buffer overflow in the font command of mIRC, probably 6.16, allows local users to execute arbitrary code via a long string. NOTE: the original researcher claims that issue has been disputed by the vendor, and that the vendor stated \"as far as I can tell, this is neither an exploit nor a vulnerability.  The above report describes a local bug in mIRC.\"  It could be that this is only exploitable by the user of the application, and thus would not cross privilege boundaries unless under an otherwise restrictive environment such as a kiosk."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:khaled_mardam-bey:mirc:6.16:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 4.6
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 3.9,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-01T02:02Z",
    "lastModifiedDate" : "2018-10-19T15:45Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0490",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "aspthai.net",
            "product" : {
              "product_data" : [ {
                "product_name" : "aspthai_forums",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.0",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://marc.info/?l=bugtraq&m=113837847503661&w=2",
          "name" : "20060127 hello",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18636",
          "name" : "18636",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/381",
          "name" : "381",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1015548",
          "name" : "1015548",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/22790",
          "name" : "22790",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16404",
          "name" : "16404",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0372",
          "name" : "ADV-2006-0372",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24359",
          "name" : "aspthai-login-sql-injection(24359)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in login.asp in ASPThai.Net ASPThai Forums 8.0 and earlier allows remote attackers to execute arbitrary SQL commands and bypass login authentication via the password field."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:aspthai.net:aspthai_forums:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "8.0"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-01T02:02Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0491",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "subzane",
            "product" : {
              "product_data" : [ {
                "product_name" : "szusermgnt",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.4",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18666",
          "name" : "18666",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/396",
          "name" : "396",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1015569",
          "name" : "1015569",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.evuln.com/vulns/53/summary.html",
          "name" : "http://www.evuln.com/vulns/53/summary.html",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/22809",
          "name" : "22809",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/423658/100/0/threaded",
          "name" : "20060201 [eVuln] SZUserMgnt Authentication Bypass",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16454",
          "name" : "16454",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0366",
          "name" : "ADV-2006-0366",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24339",
          "name" : "szusermgnt-username-sql-injection(24339)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in SZUserMgnt.class.php in SZUserMgnt 1.4 allows remote attackers to execute arbitrary SQL commands via the username parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:subzane:szusermgnt:1.4:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-01T02:02Z",
    "lastModifiedDate" : "2018-10-19T15:45Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0492",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "vincent_hor",
            "product" : {
              "product_data" : [ {
                "product_name" : "calendarix",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.6.2005-08-30",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18667",
          "name" : "18667",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/394",
          "name" : "394",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1015560",
          "name" : "1015560",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.evuln.com/vulns/52/summary.html",
          "name" : "http://www.evuln.com/vulns/52/summary.html",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/22810",
          "name" : "22810",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/22811",
          "name" : "22811",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/423656/100/0/threaded",
          "name" : "20060201 [eVuln] Calendarix SQL Injection & Authorization Bypass Vulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16456",
          "name" : "16456",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0365",
          "name" : "ADV-2006-0365",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24332",
          "name" : "calendarix-multiple-sql-injection(24332)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple SQL injection vulnerabilities in Calendarix allow remote attackers to execute arbitrary SQL commands via (1) the catview parameter in cal_functions.inc.php and (2) the login parameter in cal_login.php.  NOTE: the catview vector might overlap CVE-2005-1865."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:vincent_hor:calendarix:0.6.2005-08-30:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-01T02:02Z",
    "lastModifiedDate" : "2018-10-19T15:45Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0493",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "thomas_rybak",
            "product" : {
              "product_data" : [ {
                "product_name" : "mg2",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.5.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/17374",
          "name" : "17374",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/389",
          "name" : "389",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/423477/100/0/threaded",
          "name" : "20060130 XSS flaw in MG2 Image Gallery (v.0.5.1)",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16428",
          "name" : "16428",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24378",
          "name" : "mg2-name-xss(24378)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in MG2 (formerly known as Minigal) 0.5.1 allows remote attackers to inject arbitrary web script or HTML via the Name field in a comment associated with a picture."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:thomas_rybak:mg2:0.5.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-01T02:02Z",
    "lastModifiedDate" : "2018-10-19T15:45Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0494",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "mybulletinboard",
            "product" : {
              "product_data" : [ {
                "product_name" : "mybulletinboard",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/archive/1/423465/100/0/threaded",
          "name" : "20060130 MyBB 1.2 Local File Incusion",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24461",
          "name" : "mybb-plugins-file-include(24461)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Directory traversal vulnerability in MyBB (aka MyBulletinBoard) 1.02 allows local users with MyBB administrative privileges to include and possibly execute arbitrary local files via directory traversal sequences and a nul (%00) character in the plugin parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mybulletinboard:mybulletinboard:1.0.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:S/C:P/I:P/A:P",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 3.1,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-01T02:02Z",
    "lastModifiedDate" : "2018-10-19T15:45Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0495",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "mybulletinboard",
            "product" : {
              "product_data" : [ {
                "product_name" : "mybulletinboard",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/archive/1/423443/100/0/threaded",
          "name" : "20060129 MyBB 1.2 usercp2.php [ $url ] CrossSiteScripting ( XSS )",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16419",
          "name" : "16419",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24392",
          "name" : "mybb-usercp2-xss(24392)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in the Add Thread to Favorites feature in usercp2.php in MyBB (aka MyBulletinBoard) 1.02 allows remote attackers to inject arbitrary web script or HTML via an HTTP Referer header ($url variable)."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mybulletinboard:mybulletinboard:1.0.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-01T02:02Z",
    "lastModifiedDate" : "2018-10-19T15:45Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0496",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "mozilla",
            "product" : {
              "product_data" : [ {
                "product_name" : "firefox",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.7",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "mozilla",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.7.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.7.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.7.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.7.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.7.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.7.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.7.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.7.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.7.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.7.12",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://community.livejournal.com/lj_dev/708069.html",
          "name" : "http://community.livejournal.com/lj_dev/708069.html",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://marc.info/?l=full-disclosure&m=113847912709062&w=2",
          "name" : "20060128 -moz-binding CSS property: more XSS fun",
          "refsource" : "FULLDISC",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1015553",
          "name" : "1015553",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1015563",
          "name" : "1015563",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.davidpashley.com/cgi/pyblosxom.cgi/computing/livejournal-mozilla-bug.html",
          "name" : "http://www.davidpashley.com/cgi/pyblosxom.cgi/computing/livejournal-mozilla-bug.html",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/22924",
          "name" : "22924",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16427",
          "name" : "16427",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0403",
          "name" : "ADV-2006-0403",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://bugzilla.mozilla.org/show_bug.cgi?id=324253",
          "name" : "https://bugzilla.mozilla.org/show_bug.cgi?id=324253",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24427",
          "name" : "mozilla-mozbinding-xss(24427)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in Mozilla 1.7.12 and possibly earlier, Mozilla Firefox 1.0.7 and possibly earlier, and Netscape 8.1 and possibly earlier, allows remote attackers to inject arbitrary web script or HTML via the -moz-binding (Cascading Style Sheets) CSS property, which does not require that the style sheet have the same origin as the web page, as demonstrated by the compromise of a large number of LiveJournal accounts."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.0.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:mozilla:1.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:mozilla:1.7:alpha:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:mozilla:1.7:beta:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:mozilla:1.7:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:mozilla:1.7:rc2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:mozilla:1.7:rc3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:mozilla:1.7.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:mozilla:1.7.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:mozilla:1.7.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:mozilla:1.7.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:mozilla:1.7.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:mozilla:1.7.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:mozilla:1.7.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:mozilla:1.7.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:mozilla:1.7.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:mozilla:1.7.12:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-01T02:02Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0497",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "php_gen",
            "product" : {
              "product_data" : [ {
                "product_name" : "php_gen",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18715",
          "name" : "18715",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.eyce.be/php_gen/NEWS",
          "name" : "http://www.eyce.be/php_gen/NEWS",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/22885",
          "name" : "22885",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/15458",
          "name" : "15458",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0408",
          "name" : "ADV-2006-0408",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24441",
          "name" : "phpgen-multiple-sql-injection(24441)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple SQL injection vulnerabilities in PHP GEN before 1.4 allow remote attackers to inject arbitrary SQL commands via unknown attack vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php_gen:php_gen:0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php_gen:php_gen:0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php_gen:php_gen:0.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php_gen:php_gen:0.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php_gen:php_gen:1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php_gen:php_gen:1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php_gen:php_gen:1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php_gen:php_gen:1.3:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-01T20:46Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0498",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "php_gen",
            "product" : {
              "product_data" : [ {
                "product_name" : "php_gen",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18715",
          "name" : "18715",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.eyce.be/php_gen/NEWS",
          "name" : "http://www.eyce.be/php_gen/NEWS",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/22884",
          "name" : "22884",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0408",
          "name" : "ADV-2006-0408",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24443",
          "name" : "phpgen-parameters-xss(24443)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple cross-site scripting (XSS) vulnerabilities in PHP GEN before 1.4 allow remote attackers to inject arbitrary web script or HTML via unknown attack vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php_gen:php_gen:0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php_gen:php_gen:0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php_gen:php_gen:0.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php_gen:php_gen:0.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php_gen:php_gen:1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php_gen:php_gen:1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php_gen:php_gen:1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php_gen:php_gen:1.3:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-01T20:46Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0499",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "yourboard",
            "product" : {
              "product_data" : [ {
                "product_name" : "rlink",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18620",
          "name" : "18620",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/22818",
          "name" : "22818",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16448",
          "name" : "16448",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0390",
          "name" : "ADV-2006-0390",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24410",
          "name" : "phpbb-rlink-xss(24410)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in rlink.php in Rlink 1.0.0 module for phpBB allows remote attackers to inject arbitrary web script or HTML via the url parameter.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:yourboard:rlink:1.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-01T22:02Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0500",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "punctweb",
            "product" : {
              "product_data" : [ {
                "product_name" : "myco_guestbook",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/archive/1/423565/100/0/threaded",
          "name" : "20060131 MyCO multiple vulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24438",
          "name" : "myco-admin-information-disclosure(24438)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "MyCO Guestbook 1.0 stores the admin directory under the web document root with insufficient access control, which allows remote attackers to perform unspecified privileged actions by directly accessing files via a URL."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:punctweb:myco_guestbook:1.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-01T22:02Z",
    "lastModifiedDate" : "2018-10-19T15:45Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0501",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "punctweb",
            "product" : {
              "product_data" : [ {
                "product_name" : "myco_guestbook",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/archive/1/423565/100/0/threaded",
          "name" : "20060131 MyCO multiple vulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/423696/100/0/threaded",
          "name" : "20060201 Re: MyCO multiple vulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16444",
          "name" : "16444",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24439",
          "name" : "myco-name-xss(24439)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in MyCO Guestbook 1.0 allows remote attackers to inject arbitrary web script or HTML via the Name field, when registering a user."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:punctweb:myco_guestbook:1.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-01T22:02Z",
    "lastModifiedDate" : "2018-10-19T15:45Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0502",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "farsinews",
            "product" : {
              "product_data" : [ {
                "product_name" : "farsinews",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.1_beta2",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18637",
          "name" : "18637",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/390",
          "name" : "390",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1015554",
          "name" : "1015554",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.hamid.ir/security/farsinews.txt",
          "name" : "http://www.hamid.ir/security/farsinews.txt",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/22878",
          "name" : "22878",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/423568/100/0/threaded",
          "name" : "20060131 FarsiNews 2.1 PHP Remote File Inclusion",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16440",
          "name" : "16440",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0411",
          "name" : "ADV-2006-0411",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24419",
          "name" : "farsinews-loginout-file-include(24419)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "PHP remote file inclusion vulnerability in loginout.php in FarsiNews 2.1 Beta 2 and earlier, with register_globals enabled, allows remote attackers to include arbitrary files via a URL in the cutepath parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:farsinews:farsinews:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "2.1_beta2"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-01T22:02Z",
    "lastModifiedDate" : "2018-10-19T15:45Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0503",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "mailenable",
            "product" : {
              "product_data" : [ {
                "product_name" : "mailenable_professional",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2a",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.17",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.18",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.19",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.51",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.52",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.53",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.54",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.71",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18668",
          "name" : "18668",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1015558",
          "name" : "1015558",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.mailenable.com/professionalhistory.asp",
          "name" : "http://www.mailenable.com/professionalhistory.asp",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16457",
          "name" : "16457",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0397",
          "name" : "ADV-2006-0397",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24424",
          "name" : "mailenable-imap-examine-dos(24424)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "IMAP service in MailEnable Professional Edition before 1.72 allows remote attackers to cause a denial of service (service crash) via unspecified vectors involving the EXAMINE command."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mailenable:mailenable_professional:1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mailenable:mailenable_professional:1.2a:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mailenable:mailenable_professional:1.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mailenable:mailenable_professional:1.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mailenable:mailenable_professional:1.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mailenable:mailenable_professional:1.17:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mailenable:mailenable_professional:1.18:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mailenable:mailenable_professional:1.19:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mailenable:mailenable_professional:1.51:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mailenable:mailenable_professional:1.52:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mailenable:mailenable_professional:1.53:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mailenable:mailenable_professional:1.54:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mailenable:mailenable_professional:1.71:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-01T22:02Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0504",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "mailenable",
            "product" : {
              "product_data" : [ {
                "product_name" : "mailenable_enterprise",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.00",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.01",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.02",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.03",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.04",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18716",
          "name" : "18716",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.mailenable.com/enterprisehistory.asp",
          "name" : "http://www.mailenable.com/enterprisehistory.asp",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24517",
          "name" : "mailenable-webmail-dos(24517)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in MailEnable Enterprise Edition before 1.2 allows remote attackers to cause a denial of service (CPU utilization) by viewing \"formatted quoted-printable emails\" via webmail."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mailenable:mailenable_enterprise:1.00:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mailenable:mailenable_enterprise:1.01:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mailenable:mailenable_enterprise:1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mailenable:mailenable_enterprise:1.02:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mailenable:mailenable_enterprise:1.03:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mailenable:mailenable_enterprise:1.04:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-01T22:02Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0505",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "zbattle.net",
            "product" : {
              "product_data" : [ {
                "product_name" : "zbattle_client",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.09_sr-1_beta",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/archive/1/423431/100/0/threaded",
          "name" : "20060128 zbattle.net",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24369",
          "name" : "zbattle-command-dos(24369)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "zbattle.net Zbattle client 1.09 SR-1 beta allows remote attackers to cause an unspecified denial of service by rapidly creating and closing a game."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:zbattle.net:zbattle_client:1.09_sr-1_beta:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-01T23:02Z",
    "lastModifiedDate" : "2018-10-19T15:45Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0506",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "nuked-klan",
            "product" : {
              "product_data" : [ {
                "product_name" : "nuked-klan",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.7",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18670",
          "name" : "18670",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/385",
          "name" : "385",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/22805",
          "name" : "22805",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/423454/100/0/threaded",
          "name" : "20060130 Nuked-klaN Cross-Site Scripting Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16424",
          "name" : "16424",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0387",
          "name" : "ADV-2006-0387",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24387",
          "name" : "nukedklan-index-xss(24387)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in index.php in Nuked-klaN 1.7 allows remote attackers to inject arbitrary web script or HTML via the letter parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:nuked-klan:nuked-klan:1.7:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-01T23:02Z",
    "lastModifiedDate" : "2018-10-19T15:45Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0507",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "easy_cms",
            "product" : {
              "product_data" : [ {
                "product_name" : "easy_cms",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18673",
          "name" : "18673",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/423442/100/0/threaded",
          "name" : "20060129 EasyCMS vulnerable to XSS injection.",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/423563/100/0/threaded",
          "name" : "20060131 Re: EasyCMS vulnerable to XSS injection.",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/424431/100/0/threaded",
          "name" : "20060208 Re: Re: EasyCMS vulnerable to XSS injection.",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16430",
          "name" : "16430",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0385",
          "name" : "ADV-2006-0385",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24371",
          "name" : "easycms-xss(24371)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple cross-site scripting (XSS) vulnerabilities in Easy CMS allow remote attackers to inject arbitrary web script or HTML via (1) unknown attack vectors in the administrative interface and (2) input fields of the contact form."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:easy_cms:easy_cms:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-01T23:02Z",
    "lastModifiedDate" : "2018-10-19T15:45Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0508",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "easy_cms",
            "product" : {
              "product_data" : [ {
                "product_name" : "easy_cms",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18673",
          "name" : "18673",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/423442/100/0/threaded",
          "name" : "20060129 EasyCMS vulnerable to XSS injection.",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/424431/100/0/threaded",
          "name" : "20060208 Re: Re: EasyCMS vulnerable to XSS injection.",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24373",
          "name" : "easycms-insecure-directories(24373)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Easy CMS stores the images directory under the web document root with insufficient access control and browsing enabled, which allows remote attackers to list and possibly read images that are stored in that directory."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:easy_cms:easy_cms:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-01T23:02Z",
    "lastModifiedDate" : "2018-10-19T15:45Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0509",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "cerberus",
            "product" : {
              "product_data" : [ {
                "product_name" : "cerberus_helpdesk",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.7.1_development_release",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18657",
          "name" : "18657",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/391",
          "name" : "391",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/22843",
          "name" : "22843",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/423547/30/0/threaded",
          "name" : "20060130 Cerberus Helpdesk vulnerable to XSS",
          "refsource" : "BUGTRAQ",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16439",
          "name" : "16439",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0395",
          "name" : "ADV-2006-0395",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24388",
          "name" : "cerberus-clients-xss(24388)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple cross-site scripting (XSS) vulnerabilities in clients.php in Cerberus Helpdesk, possibly 2.7, allow remote attackers to inject arbitrary web script or HTML via (1) the contact_search parameter and (2) unspecified url fields."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cerberus:cerberus_helpdesk:2.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cerberus:cerberus_helpdesk:2.7.1_development_release:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-01T23:02Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0510",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "daffodil_software",
            "product" : {
              "product_data" : [ {
                "product_name" : "daffodil_crm",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.5",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18685",
          "name" : "18685",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/22879",
          "name" : "22879",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/423718/100/0/threaded",
          "name" : "20060130 Daffodil CRM - vulnerable to SQL-injection.",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16433",
          "name" : "16433",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0412",
          "name" : "ADV-2006-0412",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24450",
          "name" : "daffodilcrm-userlogin-sql-injection(24450)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in userlogin.jsp in Daffodil CRM 1.5 allows remote attackers to execute arbitrary SQL commands via unspecified parameters in a login action."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:daffodil_software:daffodil_crm:1.5:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-01T23:02Z",
    "lastModifiedDate" : "2018-10-19T15:45Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0511",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "blackboard",
            "product" : {
              "product_data" : [ {
                "product_name" : "blackboard",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "blackboard_academic_suite",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.osvdb.org/28023",
          "name" : "28023",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/423654/100/0/threaded",
          "name" : "20060201 Blackboard Authentication Error",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/423686/100/0/threaded",
          "name" : "20060201 Re: Blackboard Authentication Error",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/423778/100/0/threaded",
          "name" : "20060202 Re: Blackboard Authentication Error",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16438",
          "name" : "16438",
          "refsource" : "BID",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "** DISPUTED ** Blackboard Academic Suite 6.0 and earlier does not properly clear session information when de-authenticating a user who is idle, which allows subsequent users to log in as the previous user and gain privileges.  NOTE: the vendor has disputed this issue, saying that \"This is a customer specific issue related to their Kerberos authentication single sign-on application and not a vulnerability in the Blackboard product.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:blackboard:blackboard:5.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:blackboard:blackboard:5.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:blackboard:blackboard:5.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:blackboard:blackboard:5.5.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:blackboard:blackboard:6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:blackboard:blackboard_academic_suite:6.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:S/C:P/I:P/A:P",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 3.1,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-01T23:02Z",
    "lastModifiedDate" : "2018-10-19T15:45Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0512",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "padl_software",
            "product" : {
              "product_data" : [ {
                "product_name" : "migrationtools",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "46",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=338920",
          "name" : "http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=338920",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/22243",
          "name" : "22243",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2005/2427",
          "name" : "ADV-2005-2427",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://www.debian.org/security/2006/dsa-1187",
          "name" : "DSA-1187",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "PADL MigrationTools 46 creates temporary files insecurely, which allows local users to overwrite arbitrary files via a symlink attack on the temporary files, which are not properly created by (1) migrate_all_online.sh, (2) migrate_all_offline.sh, (3) migrate_all_netinfo_online.sh, (4) migrate_all_netinfo_offline.sh, (5) migrate_all_nis_online.sh, (6) migrate_all_nis_offline.sh, (7) migrate_all_nisplus_online.sh, and (8) migrate_all_nisplus_offline.sh."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:padl_software:migrationtools:46:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:N/I:P/A:N",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 2.1
        },
        "severity" : "LOW",
        "exploitabilityScore" : 3.9,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-02T11:02Z",
    "lastModifiedDate" : "2016-12-08T03:00Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0513",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "tivoli_access_manager_for_e-business",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.1.0.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.grok.org.uk/pipermail/full-disclosure/2006-February/041930.html",
          "name" : "20060203 VSR Advisory: IBM Tivoli Access Manager - Web Server Plug-in File Retrieval Vulnerability",
          "refsource" : "FULLDISC",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18725",
          "name" : "18725",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/412",
          "name" : "412",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1015582",
          "name" : "1015582",
          "refsource" : "SECTRACK",
          "tags" : [ "Exploit", "Patch" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/423946/100/0/threaded",
          "name" : "20060203 VSR Advisory: IBM Tivoli Access Manager - Web Server Plug-in File Retrieval Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16494",
          "name" : "16494",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vsecurity.com/bulletins/advisories/2006/tam-file-retrieval.txt",
          "name" : "http://www.vsecurity.com/bulletins/advisories/2006/tam-file-retrieval.txt",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0442",
          "name" : "ADV-2006-0442",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www-1.ibm.com/support/docview.wss?uid=swg24011562",
          "name" : "IY79724",
          "refsource" : "AIXAPAR",
          "tags" : [ "Patch" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24485",
          "name" : "tivoli-pkmslogout-directory-traversal(24485)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Directory traversal vulnerability in pkmslogout in Tivoli Web Server Plug-in 5.1.0.10 in Tivoli Access Manager (TAM) 5.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the filename parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tivoli_access_manager_for_e-business:5.1.0.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tivoli_access_manager_for_e-business:6.0.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-06T23:02Z",
    "lastModifiedDate" : "2018-10-19T15:45Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0515",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "cisco",
            "product" : {
              "product_data" : [ {
                "product_name" : "adaptive_security_appliance_software",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0(4)",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.1.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.4.3",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "pix_firewall",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.2.2.111",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.2.3_(110)",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.3.3_(133)",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.5(104)",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "firewall_services_module",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.1",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "pix_firewall_software",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1(6)",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1(6b)",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.2(1)",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.2(2)",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.2(5)",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.4(4)",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.4(7.202)",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.4(8)",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.1(4)",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.1(4.206)",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.2(1)",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.2(2)",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.2(3.210)",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.2(5)",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.2(6)",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.2(7)",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.2(9)",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.3(1)",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.3(1.200)",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.3(2)",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.3(3)",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0(1)",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0(2)",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0(3)",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0(4)",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0(4.101)",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1(1)",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1(2)",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1(3)",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1(4)",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1(5)",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.2(1)",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.2(2)",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.2(3)",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.2(3.100)",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.3(1)",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.3(2)",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.3(3)",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.3(3.102)",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.3(3.109)",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.3(5)",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.grok.org.uk/pipermail/full-disclosure/2006-May/045899.html",
          "name" : "20060508 VSR Advisory: WebSense content filter bypass when deployed in conjunction with Cisco filtering devices",
          "refsource" : "FULLDISC",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/20044",
          "name" : "20044",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1016039",
          "name" : "1016039",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1016040",
          "name" : "1016040",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.cisco.com/en/US/products/sw/netmgtsw/ps2032/tsd_products_security_response09186a00806824ec.html",
          "name" : "20060508 PIX/ASA/FWSM Websense/N2H2 Content Filter Bypass",
          "refsource" : "CISCO",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/25453",
          "name" : "25453",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/433270/100/0/threaded",
          "name" : "20060508 VSR Advisory: WebSense content filter bypass when deployed in conjunction with Cisco filtering devices",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/17883",
          "name" : "17883",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vsecurity.com/bulletins/advisories/2006/cisco-websense-bypass.txt",
          "name" : "http://www.vsecurity.com/bulletins/advisories/2006/cisco-websense-bypass.txt",
          "refsource" : "MISC",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/1738",
          "name" : "ADV-2006-1738",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/26308",
          "name" : "cisco-websense-content-filtering-bypass(26308)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cisco PIX/ASA 7.1.x before 7.1(2) and 7.0.x before 7.0(5), PIX 6.3.x before 6.3.5(112), and FWSM 2.3.x before 2.3(4) and 3.x before 3.1(7), when used with Websense/N2H2, allows remote attackers to bypass HTTP access restrictions by splitting the GET method of an HTTP request into multiple packets, which prevents the request from being sent to Websense for inspection, aka bugs CSCsc67612, CSCsc68472, and CSCsd81734."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "AND",
        "children" : [ {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:cisco:adaptive_security_appliance_software:7.0:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:cisco:adaptive_security_appliance_software:7.0\\(4\\):*:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:cisco:adaptive_security_appliance_software:7.0.1.4:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:cisco:adaptive_security_appliance_software:7.0.4.3:*:*:*:*:*:*:*"
          } ]
        }, {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:cisco:pix_firewall:6.2.2.111:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:cisco:pix_firewall:6.2.3_\\(110\\):*:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:cisco:pix_firewall:6.3.3_\\(133\\):*:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:h:cisco:firewall_services_module:2.3:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:h:cisco:firewall_services_module:3.1:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:o:cisco:pix_firewall:6.1.5\\(104\\):*:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:o:cisco:pix_firewall_software:2.7:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:o:cisco:pix_firewall_software:3.0:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:o:cisco:pix_firewall_software:3.1:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:o:cisco:pix_firewall_software:4.0:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:o:cisco:pix_firewall_software:4.1\\(6\\):*:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:o:cisco:pix_firewall_software:4.1\\(6b\\):*:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:o:cisco:pix_firewall_software:4.2:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:o:cisco:pix_firewall_software:4.2\\(1\\):*:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:o:cisco:pix_firewall_software:4.2\\(2\\):*:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:o:cisco:pix_firewall_software:4.2\\(5\\):*:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:o:cisco:pix_firewall_software:4.3:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:o:cisco:pix_firewall_software:4.4:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:o:cisco:pix_firewall_software:4.4\\(4\\):*:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:o:cisco:pix_firewall_software:4.4\\(7.202\\):*:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:o:cisco:pix_firewall_software:4.4\\(8\\):*:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:o:cisco:pix_firewall_software:5.0:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:o:cisco:pix_firewall_software:5.1:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:o:cisco:pix_firewall_software:5.1\\(4\\):*:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:o:cisco:pix_firewall_software:5.1\\(4.206\\):*:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:o:cisco:pix_firewall_software:5.2:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:o:cisco:pix_firewall_software:5.2\\(1\\):*:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:o:cisco:pix_firewall_software:5.2\\(2\\):*:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:o:cisco:pix_firewall_software:5.2\\(3.210\\):*:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:o:cisco:pix_firewall_software:5.2\\(5\\):*:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:o:cisco:pix_firewall_software:5.2\\(6\\):*:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:o:cisco:pix_firewall_software:5.2\\(7\\):*:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:o:cisco:pix_firewall_software:5.2\\(9\\):*:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:o:cisco:pix_firewall_software:5.3:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:o:cisco:pix_firewall_software:5.3\\(1\\):*:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:o:cisco:pix_firewall_software:5.3\\(1.200\\):*:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:o:cisco:pix_firewall_software:5.3\\(2\\):*:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:o:cisco:pix_firewall_software:5.3\\(3\\):*:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:o:cisco:pix_firewall_software:6.0:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:o:cisco:pix_firewall_software:6.0\\(1\\):*:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:o:cisco:pix_firewall_software:6.0\\(2\\):*:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:o:cisco:pix_firewall_software:6.0\\(3\\):*:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:o:cisco:pix_firewall_software:6.0\\(4\\):*:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:o:cisco:pix_firewall_software:6.0\\(4.101\\):*:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:o:cisco:pix_firewall_software:6.1:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:o:cisco:pix_firewall_software:6.1\\(1\\):*:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:o:cisco:pix_firewall_software:6.1\\(2\\):*:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:o:cisco:pix_firewall_software:6.1\\(3\\):*:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:o:cisco:pix_firewall_software:6.1\\(4\\):*:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:o:cisco:pix_firewall_software:6.1\\(5\\):*:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:o:cisco:pix_firewall_software:6.2:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:o:cisco:pix_firewall_software:6.2\\(1\\):*:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:o:cisco:pix_firewall_software:6.2\\(2\\):*:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:o:cisco:pix_firewall_software:6.2\\(3\\):*:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:o:cisco:pix_firewall_software:6.2\\(3.100\\):*:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:o:cisco:pix_firewall_software:6.3:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:o:cisco:pix_firewall_software:6.3\\(1\\):*:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:o:cisco:pix_firewall_software:6.3\\(2\\):*:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:o:cisco:pix_firewall_software:6.3\\(3\\):*:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:o:cisco:pix_firewall_software:6.3\\(3.102\\):*:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:o:cisco:pix_firewall_software:6.3\\(3.109\\):*:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:o:cisco:pix_firewall_software:6.3\\(5\\):*:*:*:*:*:*:*"
          } ]
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-05-09T10:02Z",
    "lastModifiedDate" : "2018-10-30T16:26Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0516",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "sun",
            "product" : {
              "product_data" : [ {
                "product_name" : "solaris",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18671",
          "name" : "18671",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1015557",
          "name" : "1015557",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://sunsolve.sun.com/search/document.do?assetkey=1-26-102149-1",
          "name" : "102149",
          "refsource" : "SUNALERT",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16460",
          "name" : "16460",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0394",
          "name" : "ADV-2006-0394",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24395",
          "name" : "solaris-x64-kernel-dos(24395)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1163",
          "name" : "oval:org.mitre.oval:def:1163",
          "refsource" : "OVAL",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A219",
          "name" : "oval:org.mitre.oval:def:219",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the kernel processing in Solaris 10 64 bit platform, when running in 64-bit mode, allows local users to cause a denial of service (system panic) via unknown attack vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:sun:solaris:10.0:*:64_bit:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 2.1
        },
        "severity" : "LOW",
        "exploitabilityScore" : 3.9,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-02T11:02Z",
    "lastModifiedDate" : "2017-10-11T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0517",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "spip",
            "product" : {
              "product_data" : [ {
                "product_name" : "spip",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.8.2e",
                    "version_affected" : "<="
                  }, {
                    "version_value" : "1.9_alpha2_5539",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://archives.neohapsis.com/archives/fulldisclosure/2006-01/0990.html",
          "name" : "20060131 ZRCSA-200601: SPIP - Multiple Vulnerabilities",
          "refsource" : "FULLDISC",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18676",
          "name" : "18676",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/395",
          "name" : "395",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1015556",
          "name" : "1015556",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/22844",
          "name" : "22844",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/22845",
          "name" : "22845",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/22848",
          "name" : "22848",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/423655/100/0/threaded",
          "name" : "20060131 ZRCSA-200601: SPIP - Multiple Vulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16458",
          "name" : "16458",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/24397",
          "name" : "24397",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0398",
          "name" : "ADV-2006-0398",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.zone-h.org/en/advisories/read/id=8650/",
          "name" : "http://www.zone-h.org/en/advisories/read/id=8650/",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Patch", "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24397",
          "name" : "spip-forum-sql-injection(24397)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple SQL injection vulnerabilities in formulaires/inc-formulaire_forum.php3 in SPIP 1.8.2-e and earlier and 1.9 Alpha 2 (5539) and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id_forum, (2) id_article, or (3) id_breve parameters to forum.php3; (4) unspecified vectors related to \"session handling\"; and (5) when posting \"petitions\"."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:spip:spip:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.8.2e"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:spip:spip:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.9_alpha2_5539"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-02T11:02Z",
    "lastModifiedDate" : "2018-10-19T15:45Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0518",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "spip",
            "product" : {
              "product_data" : [ {
                "product_name" : "spip",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.8.2e",
                    "version_affected" : "<="
                  }, {
                    "version_value" : "1.9_alpha2_5539",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18676",
          "name" : "18676",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/22849",
          "name" : "22849",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16461",
          "name" : "16461",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0398",
          "name" : "ADV-2006-0398",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.zone-h.org/en/advisories/read/id=8650/",
          "name" : "http://www.zone-h.org/en/advisories/read/id=8650/",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24401",
          "name" : "spip-index-xss(24401)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in index.php3 in SPIP 1.8.2-e and earlier and 1.9 Alpha 2 (5539) and earlier allows remote attackers to inject arbitrary web script or HTML via the lang parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:spip:spip:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.8.2e"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:spip:spip:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.9_alpha2_5539"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-02T11:02Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0519",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "spip",
            "product" : {
              "product_data" : [ {
                "product_name" : "spip",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.8.2e",
                    "version_affected" : "<="
                  }, {
                    "version_value" : "1.9_alpha2_5539",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18676",
          "name" : "18676",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0398",
          "name" : "ADV-2006-0398",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.zone-h.org/en/advisories/read/id=8650/",
          "name" : "http://www.zone-h.org/en/advisories/read/id=8650/",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24399",
          "name" : "spip-incmessforum-path-disclosure(24399)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SPIP 1.8.2-e and earlier and 1.9 Alpha 2 (5539) and earlier allows remote attackers to obtain sensitive information via a direct request to inc-messforum.php3, which reveals the path in an error message."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:spip:spip:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.8.2e"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:spip:spip:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.9_alpha2_5539"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-02T11:02Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0520",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "dragoran",
            "product" : {
              "product_data" : [ {
                "product_name" : "portal_module",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18664",
          "name" : "18664",
          "refsource" : "SECUNIA",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/22851",
          "name" : "22851",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16447",
          "name" : "16447",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0396",
          "name" : "ADV-2006-0396",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24404",
          "name" : "portal-index-sql-injection(24404)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability index.php in Dragoran Portal module 1.3 for Invision Power Board (IPB) allows remote attackers to execute arbitrary SQL commands via the site parameter.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:dragoran:portal_module:1.3:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-02T11:02Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0521",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "browsercrm",
            "product" : {
              "product_data" : [ {
                "product_name" : "browsercrm",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18658",
          "name" : "18658",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/393",
          "name" : "393",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/22841",
          "name" : "22841",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/423546/100/0/threaded",
          "name" : "20060131 BrowserCRM vulnerable for XSS",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16435",
          "name" : "16435",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0391",
          "name" : "ADV-2006-0391",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24390",
          "name" : "browsercrm-results-xss(24390)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in results.php in BrowserCRM allows remote attackers to inject arbitrary web script or HTML via certain manipulations of the query parameter, as demonstrated using an IMG SRC tag."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:browsercrm:browsercrm:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-02T11:02Z",
    "lastModifiedDate" : "2018-10-19T15:45Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0522",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "symantec",
            "product" : {
              "product_data" : [ {
                "product_name" : "sygate_management_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.5_mr_3_build_894_english",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0_mr_1_build_1104_english",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1_ga_build_1258_japanese",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1_mr1_build_1351_chinese",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1_mr_2_build_1417_english",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18689",
          "name" : "18689",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securityresponse.symantec.com/avcenter/security/Content/2006.02.01.html",
          "name" : "http://securityresponse.symantec.com/avcenter/security/Content/2006.02.01.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1015561",
          "name" : "1015561",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/22883",
          "name" : "22883",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16452",
          "name" : "16452",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0402",
          "name" : "ADV-2006-0402",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24413",
          "name" : "symantec-sms-sql-injection(24413)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in the Authentication Servlet in Symantec Sygate Management Server (SMS) version 4.1 build 1417 and earlier allows remote attackers to execute arbitrary SQL commands and bypass authentication via unknown attack vectors related to a URL."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:sygate_management_server:3.5_mr_3_build_894_english:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:sygate_management_server:4.0_mr_1_build_1104_english:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:sygate_management_server:4.1_ga_build_1258_japanese:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:sygate_management_server:4.1_mr1_build_1351_chinese:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:symantec:sygate_management_server:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "4.1_mr_2_build_1417_english"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-02T11:02Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0523",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "mybulletinboard",
            "product" : {
              "product_data" : [ {
                "product_name" : "mybulletinboard",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0_final",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0_pr2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0_preview_release_2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0_rc2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0_rc4",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://community.mybboard.net/showthread.php?tid=6418",
          "name" : "http://community.mybboard.net/showthread.php?tid=6418",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18678",
          "name" : "18678",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/22903",
          "name" : "22903",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0400",
          "name" : "ADV-2006-0400",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24416",
          "name" : "mybb-global-sql-injection(24416)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in global.php in MyBB before 1.03 allows remote attackers to execute arbitrary SQL commands via the templatelist variable."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mybulletinboard:mybulletinboard:1.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mybulletinboard:mybulletinboard:1.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mybulletinboard:mybulletinboard:1.0_final:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mybulletinboard:mybulletinboard:1.0_pr2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mybulletinboard:mybulletinboard:1.0_preview_release_2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mybulletinboard:mybulletinboard:1.0_rc2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mybulletinboard:mybulletinboard:1.0_rc4:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-02T11:02Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0524",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ashwebstudio",
            "product" : {
              "product_data" : [ {
                "product_name" : "ashnews",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.83",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://archives.neohapsis.com/archives/fulldisclosure/2006-01/0955.html",
          "name" : "20060130 ashnews Cross-Site Scripting Vulnerability",
          "refsource" : "FULLDISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://archives.neohapsis.com/archives/fulldisclosure/2006-01/0969.html",
          "name" : "20060130 Re: ashnews Cross-Site Scripting Vulnerability",
          "refsource" : "FULLDISC",
          "tags" : [ ]
        }, {
          "url" : "http://archives.neohapsis.com/archives/fulldisclosure/2006-01/0979.html",
          "name" : "20060131 Re: ashnews Cross-Site Scripting Vulnerability",
          "refsource" : "FULLDISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://secunia.com/advisories/9331",
          "name" : "9331",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/22934",
          "name" : "22934",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16426",
          "name" : "16426",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24365",
          "name" : "ashnews-ashnews-xss(24365)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in ashnews.php in Derek Ashauer ashNews 0.83 allows remote attackers to inject arbitrary web script or HTML via the id parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ashwebstudio:ashnews:0.83:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-02T11:02Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0525",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "adobe",
            "product" : {
              "product_data" : [ {
                "product_name" : "acrobat",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.5a",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.5c",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.3",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "acrobat_reader",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.5a",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.5c",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.3",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "creative_suite",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "illustrator",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "cs",
                    "version_affected" : "="
                  }, {
                    "version_value" : "cs3",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "indesign",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "cs",
                    "version_affected" : "="
                  }, {
                    "version_value" : "cs3",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "pagemaker",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "photoshop",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "le",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "premiere",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.5",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "version_cue",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "gold",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-264"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18698",
          "name" : "18698",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1015577",
          "name" : "1015577",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1015578",
          "name" : "1015578",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1015579",
          "name" : "1015579",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.adobe.com/support/techdocs/332644.html",
          "name" : "http://www.adobe.com/support/techdocs/332644.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.cs.princeton.edu/~sudhakar/papers/winval.pdf",
          "name" : "http://www.cs.princeton.edu/~sudhakar/papers/winval.pdf",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/953860",
          "name" : "VU#953860",
          "refsource" : "CERT-VN",
          "tags" : [ "Third Party Advisory", "US Government Resource" ]
        }, {
          "url" : "http://www.osvdb.org/22908",
          "name" : "22908",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/423587/100/0/threaded",
          "name" : "20060131 Windows Access Control Demystified",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16451",
          "name" : "16451",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0431",
          "name" : "ADV-2006-0431",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24464",
          "name" : "adobe-insecure-default-permissions(24464)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple Adobe products, including (1) Photoshop CS2, (2) Illustrator CS2, and (3) Adobe Help Center, install a large number of .EXE and .DLL files with write-access permission for the Everyone group, which allows local users to gain privileges via Trojan horse programs."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat:3.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat:3.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat:4.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat:4.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat:4.0.5a:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat:4.0.5c:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat:5.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat:5.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat:5.0.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat:6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat:6.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat:6.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat:6.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat:6.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat:7.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat:7.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat:7.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat:7.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat_reader:3.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat_reader:4.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat_reader:4.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat_reader:4.0.5a:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat_reader:4.0.5c:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat_reader:4.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat_reader:5.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat_reader:5.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat_reader:5.0.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat_reader:5.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat_reader:6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat_reader:6.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat_reader:6.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat_reader:6.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat_reader:6.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat_reader:7.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat_reader:7.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat_reader:7.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:acrobat_reader:7.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:creative_suite:1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:creative_suite:1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:creative_suite:2.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:illustrator:7.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:illustrator:8.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:illustrator:9.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:illustrator:10.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:illustrator:cs:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:illustrator:cs3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:indesign:cs:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:indesign:cs3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:pagemaker:6.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:pagemaker:6.5:*:plus:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:pagemaker:7.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:pagemaker:7.0:*:plus:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:photoshop:7.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:photoshop:8.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:photoshop:9.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:photoshop:le:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:premiere:1.5:*:pro:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:version_cue:1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:version_cue:1.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:adobe:version_cue:gold:*:mac_os_x:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 4.6
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 3.9,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-02T11:02Z",
    "lastModifiedDate" : "2018-10-19T15:45Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0526",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "aol",
            "product" : {
              "product_data" : [ {
                "product_name" : "aol_client_software",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.cs.princeton.edu/~sudhakar/papers/winval.pdf",
          "name" : "http://www.cs.princeton.edu/~sudhakar/papers/winval.pdf",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/953860",
          "name" : "VU#953860",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/423587/100/0/threaded",
          "name" : "20060131 Windows Access Control Demystified",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16453",
          "name" : "16453",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24498",
          "name" : "aol-insecure-default-permissions(24498)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The default configuration of the America Online (AOL) client software allows all users to modify a certain registry value that specifies a DLL file name, which might allow local users to gain privileges via a Trojan horse program."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:aol:aol_client_software:8.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:aol:aol_client_software:8.0:*:plus:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:aol:aol_client_software:9.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:aol:aol_client_software:9.0:*:optimized:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:aol:aol_client_software:9.0:*:security:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.2
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 3.9,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-02T11:02Z",
    "lastModifiedDate" : "2018-10-19T15:45Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0527",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "isc",
            "product" : {
              "product_data" : [ {
                "product_name" : "bind",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-264"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://attrition.org/pipermail/vim/2006-February/000551.html",
          "name" : "20060216 Recent HP advisories outline BIND problems",
          "refsource" : "VIM",
          "tags" : [ ]
        }, {
          "url" : "http://computerworld.com/networkingtopics/networking/story/0,10801,103744,00.html",
          "name" : "http://computerworld.com/networkingtopics/networking/story/0,10801,103744,00.html",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18690",
          "name" : "18690",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/438",
          "name" : "438",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/748",
          "name" : "748",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1015551",
          "name" : "1015551",
          "refsource" : "SECTRACK",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://securitytracker.com/id?1015606",
          "name" : "1015606",
          "refsource" : "SECTRACK",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.osvdb.org/22888",
          "name" : "22888",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/425083/100/0/threaded",
          "name" : "SSRT051045",
          "refsource" : "HP",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16455",
          "name" : "16455",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0399",
          "name" : "ADV-2006-0399",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=c00595837",
          "name" : "HPSBTU02095",
          "refsource" : "HP",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24414",
          "name" : "tru64-dns-bind-unauth-access(24414)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "BIND 4 (BIND4) and BIND 8 (BIND8), if used as a target forwarder, allows remote attackers to gain privileged access via a \"Kashpureff-style DNS cache corruption\" attack."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:isc:bind:4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:isc:bind:8:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-02T11:02Z",
    "lastModifiedDate" : "2018-10-19T15:45Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0528",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "gnome",
            "product" : {
              "product_data" : [ {
                "product_name" : "evolution",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.3.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.3.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.3.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.3.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.3.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.3.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.3.6.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.3.7",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://archives.neohapsis.com/archives/fulldisclosure/2006-01/0925.html",
          "name" : "20060128 gnome evolution mail client inline text file DoS issue",
          "refsource" : "FULLDISC",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/19504",
          "name" : "19504",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/610",
          "name" : "610",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDKSA-2006:057",
          "name" : "MDKSA-2006:057",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.novell.com/linux/security/advisories/2006_07_sr.html",
          "name" : "SUSE-SR:2006:007",
          "refsource" : "SUSE",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16408",
          "name" : "16408",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://usn.ubuntu.com/265-1/",
          "name" : "USN-265-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The cairo library (libcairo), as used in GNOME Evolution and possibly other products, allows remote attackers to cause a denial of service (persistent client crash) via an attached text file that contains \"Content-Disposition: inline\" in the header, and a very long line in the body, which causes the client to repeatedly crash until the e-mail message is manually removed, possibly due to a buffer overflow, as demonstrated using an XML attachment."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:gnome:evolution:2.3.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:gnome:evolution:2.3.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:gnome:evolution:2.3.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:gnome:evolution:2.3.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:gnome:evolution:2.3.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:gnome:evolution:2.3.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:gnome:evolution:2.3.6.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:gnome:evolution:2.3.7:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-02T11:02Z",
    "lastModifiedDate" : "2018-10-03T21:35Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0529",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ca",
            "product" : {
              "product_data" : [ {
                "product_name" : "messaging",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.05",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.07.210.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.07.220.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.07.220.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.07.220.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.07.220.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.07.220.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.07.220.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.07.220.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.07.220.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.07.220.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.07.220.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.07.220.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.07.220.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.07.220.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.11.18.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.11.19.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.11.21",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.11.22",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.11.23",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.11.24",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.11.25",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.11.26",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.11.26.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.11.26.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.11.26.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.11.26.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.11.26.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.11.26.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.11.26.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.11.27.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.11.27.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.11.27.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.11.27.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.11.28.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.11.29.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.11.29.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.11.29.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.11.29.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.11.29.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.11.29.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.11.29.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.11.29.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.11.29.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.11.29.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.11.29.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.11.29.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.11.29.16",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.11.29.17",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.11.29.18",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.11.29.19",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18681",
          "name" : "18681",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1015571",
          "name" : "1015571",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://supportconnectw.ca.com/public/ca_common_docs/camessagsecurity_notice.asp",
          "name" : "http://supportconnectw.ca.com/public/ca_common_docs/camessagsecurity_notice.asp",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/21146",
          "name" : "21146",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/423785/100/0/threaded",
          "name" : "20060202 CAID 33581 - CA Message Queuing Denial of Service Vulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16475",
          "name" : "16475",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0414",
          "name" : "ADV-2006-0414",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www3.ca.com/securityadvisor/vulninfo/vuln.aspx?id=33581",
          "name" : "http://www3.ca.com/securityadvisor/vulninfo/vuln.aspx?id=33581",
          "refsource" : "MISC",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24448",
          "name" : "ca-cam-port4105-dos(24448)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Computer Associates (CA) Message Queuing (CAM / CAFT) before 1.07 Build 220_16 and 1.11 Build 29_20, as used in multiple CA products, allows remote attackers to cause a denial of service via a crafted message to TCP port 4105."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.05:*:aix:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.05:*:linux:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.05:*:solaris:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.05:*:windows:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.07.210.0:*:aix:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.07.210.0:*:solaris:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.07.220.0:*:solaris:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.07.220.0:*:windows:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.07.220.3:*:windows:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.07.220.4:*:windows:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.07.220.5:*:aix:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.07.220.5:*:hp_ux:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.07.220.5:*:solaris:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.07.220.5:*:windows:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.07.220.6:*:windows:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.07.220.7:*:aix:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.07.220.7:*:hp_ux:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.07.220.7:*:windows:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.07.220.8:*:aix:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.07.220.8:*:hp_ux:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.07.220.8:*:solaris:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.07.220.9:*:solaris:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.07.220.9:*:windows:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.07.220.10:*:windows:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.07.220.11:*:aix:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.07.220.11:*:hp_ux:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.07.220.11:*:linux:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.07.220.11:*:solaris:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.07.220.11:*:windows:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.07.220.13:*:aix:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.07.220.13:*:hp_ux:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.07.220.13:*:linux:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.07.220.13:*:solaris:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.07.220.13:*:windows:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.07.220.14:*:aix:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.07.220.14:*:hp_ux:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.07.220.14:*:linux:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.07.220.14:*:solaris:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.07.220.14:*:windows:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.07.220.15:*:aix:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.07.220.15:*:hp_ux:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.07.220.15:*:linux:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.07.220.15:*:solaris:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.07.220.15:*:windows:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.18.0:*:hp_ux:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.19.0:*:aix:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.19.0:*:solaris:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.21:*:windows:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.22:*:windows:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.23:*:windows:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.24:*:windows:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.25:*:windows:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.26:*:windows:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.26.1:*:windows:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.26.2:*:windows:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.26.6:*:windows:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.26.7:*:windows:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.26.8:*:windows:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.26.9:*:windows:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.26.10:*:windows:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.27.0:*:aix:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.27.0:*:hp_ux:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.27.0:*:solaris:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.27.1:*:aix:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.27.1:*:hp_ux:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.27.1:*:solaris:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.27.1:*:windows:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.27.2:*:windows:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.27.3:*:windows:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.28.0:*:linux:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.29.0:*:windows:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.29.2:*:aix:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.29.2:*:hp_ux:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.29.2:*:solaris:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.29.2:*:windows:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.29.3:*:aix:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.29.3:*:hp_ux:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.29.3:*:solaris:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.29.3:*:windows:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.29.4:*:aix:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.29.4:*:hp_ux:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.29.4:*:solaris:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.29.4:*:windows:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.29.5:*:aix:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.29.5:*:hp_ux:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.29.5:*:linux:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.29.5:*:solaris:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.29.5:*:windows:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.29.6:*:windows:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.29.7:*:windows:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.29.8:*:aix:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.29.8:*:hp_ux:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.29.8:*:linux:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.29.8:*:solaris:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.29.8:*:windows:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.29.9:*:aix:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.29.9:*:hp_ux:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.29.9:*:linux:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.29.9:*:solaris:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.29.9:*:windows:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.29.13:*:aix:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.29.13:*:hp_ux:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.29.13:*:linux:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.29.13:*:solaris:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.29.13:*:windows:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.29.14:*:aix:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.29.14:*:hp_ux:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.29.14:*:linux:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.29.14:*:solaris:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.29.14:*:windows:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.29.15:*:aix:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.29.15:*:hp_ux:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.29.15:*:linux:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.29.15:*:solaris:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.29.15:*:windows:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.29.16:*:aix:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.29.16:*:hp_ux:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.29.16:*:linux:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.29.16:*:solaris:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.29.16:*:windows:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.29.17:*:aix:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.29.17:*:hp_ux:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.29.17:*:linux:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.29.17:*:solaris:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.29.17:*:windows:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.29.18:*:aix:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.29.18:*:hp_ux:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.29.18:*:linux:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.29.18:*:solaris:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.29.18:*:windows:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.29.19:*:aix:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.29.19:*:hp_ux:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.29.19:*:linux:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.29.19:*:solaris:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.29.19:*:windows:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-02T20:06Z",
    "lastModifiedDate" : "2018-10-19T15:45Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0530",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ca",
            "product" : {
              "product_data" : [ {
                "product_name" : "messaging",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.05",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.07.210.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.07.220.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.07.220.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.07.220.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.07.220.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.07.220.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.07.220.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.07.220.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.07.220.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.07.220.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.07.220.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.07.220.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.07.220.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.07.220.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.11.18.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.11.19.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.11.21",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.11.22",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.11.23",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.11.24",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.11.25",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.11.26",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.11.26.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.11.26.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.11.26.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.11.26.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.11.26.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.11.26.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.11.26.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.11.27.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.11.27.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.11.27.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.11.27.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.11.28.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.11.29.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.11.29.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.11.29.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.11.29.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.11.29.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.11.29.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.11.29.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.11.29.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.11.29.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.11.29.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.11.29.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.11.29.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.11.29.16",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.11.29.17",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.11.29.18",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.11.29.19",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18681",
          "name" : "18681",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/404",
          "name" : "404",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1015571",
          "name" : "1015571",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/423785/100/0/threaded",
          "name" : "20060202 CAID 33581 - CA Message Queuing Denial of Service Vulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16475",
          "name" : "16475",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0414",
          "name" : "ADV-2006-0414",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www3.ca.com/securityadvisor/vulninfo/vuln.aspx?id=33581",
          "name" : "http://www3.ca.com/securityadvisor/vulninfo/vuln.aspx?id=33581",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24449",
          "name" : "ca-cam-spoofed-message-dos(24449)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Computer Associates (CA) Message Queuing (CAM / CAFT) before 1.07 Build 220_16 and 1.11 Build 29_20, as used in multiple CA products, allows remote attackers to cause a denial of service via spoofed CAM control messages."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.05:*:aix:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.05:*:hp_ux:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.05:*:linux:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.05:*:solaris:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.05:*:windows:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.07.210.0:*:aix:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.07.210.0:*:solaris:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.07.220.0:*:solaris:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.07.220.0:*:windows:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.07.220.3:*:windows:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.07.220.4:*:windows:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.07.220.5:*:aix:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.07.220.5:*:hp_ux:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.07.220.5:*:solaris:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.07.220.5:*:windows:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.07.220.6:*:windows:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.07.220.7:*:aix:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.07.220.7:*:hp_ux:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.07.220.7:*:windows:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.07.220.8:*:aix:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.07.220.8:*:hp_ux:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.07.220.8:*:solaris:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.07.220.9:*:solaris:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.07.220.9:*:windows:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.07.220.10:*:windows:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.07.220.11:*:aix:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.07.220.11:*:hp_ux:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.07.220.11:*:linux:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.07.220.11:*:solaris:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.07.220.11:*:windows:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.07.220.13:*:aix:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.07.220.13:*:hp_ux:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.07.220.13:*:linux:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.07.220.13:*:solaris:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.07.220.13:*:windows:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.07.220.14:*:aix:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.07.220.14:*:hp_ux:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.07.220.14:*:linux:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.07.220.14:*:solaris:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.07.220.14:*:windows:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.07.220.15:*:aix:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.07.220.15:*:hp_ux:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.07.220.15:*:linux:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.07.220.15:*:solaris:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.07.220.15:*:windows:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.18.0:*:hp_ux:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.19.0:*:aix:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.19.0:*:solaris:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.21:*:windows:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.22:*:windows:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.23:*:windows:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.24:*:windows:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.25:*:windows:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.26:*:windows:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.26.1:*:windows:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.26.2:*:windows:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.26.6:*:windows:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.26.7:*:windows:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.26.8:*:windows:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.26.9:*:windows:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.26.10:*:windows:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.27.0:*:aix:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.27.0:*:hp_ux:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.27.0:*:solaris:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.27.1:*:aix:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.27.1:*:hp_ux:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.27.1:*:solaris:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.27.1:*:windows:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.27.2:*:windows:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.27.3:*:windows:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.28.0:*:linux:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.29.0:*:windows:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.29.2:*:aix:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.29.2:*:hp_ux:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.29.2:*:solaris:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.29.2:*:windows:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.29.3:*:aix:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.29.3:*:hp_ux:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.29.3:*:solaris:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.29.3:*:windows:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.29.4:*:aix:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.29.4:*:hp_ux:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.29.4:*:solaris:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.29.4:*:windows:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.29.5:*:aix:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.29.5:*:hp_ux:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.29.5:*:linux:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.29.5:*:solaris:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.29.5:*:windows:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.29.6:*:windows:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.29.7:*:windows:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.29.8:*:aix:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.29.8:*:hp_ux:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.29.8:*:linux:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.29.8:*:solaris:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.29.8:*:windows:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.29.9:*:aix:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.29.9:*:hp_ux:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.29.9:*:linux:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.29.9:*:solaris:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.29.9:*:windows:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.29.13:*:aix:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.29.13:*:hp_ux:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.29.13:*:linux:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.29.13:*:solaris:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.29.13:*:windows:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.29.14:*:aix:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.29.14:*:hp_ux:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.29.14:*:linux:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.29.14:*:solaris:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.29.14:*:windows:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.29.15:*:aix:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.29.15:*:hp_ux:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.29.15:*:linux:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.29.15:*:solaris:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.29.15:*:windows:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.29.16:*:aix:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.29.16:*:hp_ux:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.29.16:*:linux:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.29.16:*:solaris:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.29.16:*:windows:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.29.17:*:aix:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.29.17:*:hp_ux:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.29.17:*:linux:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.29.17:*:solaris:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.29.17:*:windows:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.29.18:*:aix:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.29.18:*:hp_ux:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.29.18:*:linux:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.29.18:*:solaris:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.29.18:*:windows:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.29.19:*:aix:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.29.19:*:hp_ux:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.29.19:*:linux:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.29.19:*:solaris:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ca:messaging:1.11.29.19:*:windows:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-02T20:06Z",
    "lastModifiedDate" : "2018-10-19T15:45Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0531",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "sun",
            "product" : {
              "product_data" : [ {
                "product_name" : "java_system_access_manager",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18699",
          "name" : "18699",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1015567",
          "name" : "1015567",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://sunsolve.sun.com/search/document.do?assetkey=1-26-102140-1",
          "name" : "102140",
          "refsource" : "SUNALERT",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16474",
          "name" : "16474",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0430",
          "name" : "ADV-2006-0430",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24423",
          "name" : "sun-jsam-admin-access(24423)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A360",
          "name" : "oval:org.mitre.oval:def:360",
          "refsource" : "OVAL",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A755",
          "name" : "oval:org.mitre.oval:def:755",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in Sun Java System Access Manager 7.0 allows local users logged in as \"root\" to bypass authentication and gain top-level administrator privileges via the amadmin CLI tool."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sun:java_system_access_manager:7.0:*:linux:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sun:java_system_access_manager:7.0:*:solaris_s:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sun:java_system_access_manager:7.0:*:solaris_x:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.2
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 3.9,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-04T00:06Z",
    "lastModifiedDate" : "2017-10-11T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0532",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "media2_cms",
            "product" : {
              "product_data" : [ {
                "product_name" : "shop",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18683",
          "name" : "18683",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/400",
          "name" : "400",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/22911",
          "name" : "22911",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/423768",
          "name" : "20060201 SoftMaker Shop is vulnerable to XSS",
          "refsource" : "BUGTRAQ",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16471",
          "name" : "16471",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0434",
          "name" : "ADV-2006-0434",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24451",
          "name" : "softmakershop-image-xss(24451)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in resultat.asp in SoftMaker Shop allows remote attackers to inject arbitrary web script or HTML via a strSok parameter containing a javascript: URI in an IMG SRC attribute."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:media2_cms:shop:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-04T00:06Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0533",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "cpanel",
            "product" : {
              "product_data" : [ {
                "product_name" : "cpanel",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://marc.info/?l=full-disclosure&m=113894933522271&w=2",
          "name" : "20060203 Re: cPanel Multiple Cross Site Scripting",
          "refsource" : "FULLDISC",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18691",
          "name" : "18691",
          "refsource" : "SECUNIA",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/22906",
          "name" : "22906",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0433",
          "name" : "ADV-2006-0433",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24468",
          "name" : "cpanel-scripts-xss(24468)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in webmailaging.cgi in cPanel allows remote attackers to inject arbitrary web script or HTML via the numdays parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cpanel:cpanel:-:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-04T00:06Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0534",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "cybershop",
            "product" : {
              "product_data" : [ {
                "product_name" : "asp_ultimate_e-commerce_script",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18730",
          "name" : "18730",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/401",
          "name" : "401",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/423787/100/0/threaded",
          "name" : "20060202 CyberShop Ultimate E-commerce Script Cross Site Scripting",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16473",
          "name" : "16473",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24454",
          "name" : "cybershop-xss(24454)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple cross-site scripting (XSS) vulnerabilities in default.asp in CyberShop Ultimate E-commerce allow remote attackers to inject arbitrary web script or HTML via the (1) ortak or (2) kat parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cybershop:asp_ultimate_e-commerce_script:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-04T00:06Z",
    "lastModifiedDate" : "2018-10-19T15:45Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0535",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "communityserver.org",
            "product" : {
              "product_data" : [ {
                "product_name" : "community_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/16478",
          "name" : "16478",
          "refsource" : "BID",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple cross-site scripting (XSS) vulnerabilities in Community Server allow remote attackers to inject arbitrary web script or HTML via unknown attack vectors.  NOTE: this candidate does not contain any actionable or distinguishing information.  Perhaps it should not be included in CVE.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:communityserver.org:community_server:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2006-02-04T00:06Z",
    "lastModifiedDate" : "2008-09-05T20:59Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0536",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "neomail",
            "product" : {
              "product_data" : [ {
                "product_name" : "neomail",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.27",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://securitytracker.com/id?1015581",
          "name" : "1015581",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/22978",
          "name" : "22978",
          "refsource" : "OSVDB",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/423901/100/0/threaded",
          "name" : "20060203 Neomail Cross Site Scripting Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0449",
          "name" : "ADV-2006-0449",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24470",
          "name" : "neomail-neomail-script-xss(24470)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in neomail.pl in NeoMail 1.27 allows remote attackers to inject arbitrary web script or HTML via the sort parameter.  NOTE: some sources say that the affected parameter is \"date,\" but the demonstration URL shows that it is \"sort\"."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:neomail:neomail:1.27:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-04T00:06Z",
    "lastModifiedDate" : "2018-10-19T15:45Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0537",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "kinesphere_corporation",
            "product" : {
              "product_data" : [ {
                "product_name" : "exchange_pop3",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.0_build_050203",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://archives.neohapsis.com/archives/bugtraq/2006-02/0040.html",
          "name" : "20060203 Exchangepop3 rcpt buffer overflow vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://downloads.securityfocus.com/vulnerabilities/exploits/exchangepop3.pl",
          "name" : "http://downloads.securityfocus.com/vulnerabilities/exploits/exchangepop3.pl",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://secunia.com/advisories/18687",
          "name" : "18687",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/408",
          "name" : "408",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1015580",
          "name" : "1015580",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/22907",
          "name" : "22907",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16485",
          "name" : "16485",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0437",
          "name" : "ADV-2006-0437",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24477",
          "name" : "exchangepop3-rcptto-bo(24477)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/1466",
          "name" : "1466",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Buffer overflow in the POP3 server in Kinesphere Corporation eXchange before 5.0.060125 allows remote attackers to execute arbitrary code via a long RCPT TO argument."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:kinesphere_corporation:exchange_pop3:5.0_build_050203:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-04T00:06Z",
    "lastModifiedDate" : "2017-10-11T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0538",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ciphertrust",
            "product" : {
              "product_data" : [ {
                "product_name" : "ironmail",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.0.1",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://securityreason.com/securityalert/407",
          "name" : "407",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1015555",
          "name" : "1015555",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/423898/100/0/threaded",
          "name" : "20060203 IronMail-5.0.1-Denial of-Service-Protection-Lets-Remote-Users-Deny-Service",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16465",
          "name" : "16465",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24445",
          "name" : "ironmail-tcpsyn-flood-dos(24445)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "CipherTrust IronMail 5.0.1, when \"Denial of Service Protection\" is enabled, allows remote attackers to cause a denial of service (possibly CPU consumption) via a SYN flood with malformed TCP packets from multiple connections."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ciphertrust:ironmail:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "5.0.1"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:H/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "HIGH",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 2.6
        },
        "severity" : "LOW",
        "exploitabilityScore" : 4.9,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-04T00:06Z",
    "lastModifiedDate" : "2018-10-19T15:45Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0539",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "thibault_godouet",
            "product" : {
              "product_data" : [ {
                "product_name" : "fcron",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.0.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://archives.neohapsis.com/archives/fulldisclosure/2006-01/0999.html",
          "name" : "20060201 Fcrontab - memory corruption on heap.",
          "refsource" : "FULLDISC",
          "tags" : [ ]
        }, {
          "url" : "http://fcron.free.fr/doc/en/changes.html",
          "name" : "http://fcron.free.fr/doc/en/changes.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://fcron.free.fr/news.php#a20060206a.xml",
          "name" : "http://fcron.free.fr/news.php#a20060206a.xml",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18719",
          "name" : "18719",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/423697/100/0/threaded",
          "name" : "20060201 Fcrontab - memory corruption on heap.",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16467",
          "name" : "16467",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.trustix.org/errata/2006/0036",
          "name" : "2006-0036",
          "refsource" : "TRUSTIX",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0435",
          "name" : "ADV-2006-0435",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://bugs.trustix.org/show_bug.cgi?id=1754",
          "name" : "https://bugs.trustix.org/show_bug.cgi?id=1754",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24444",
          "name" : "fcron-syslog-bo(24444)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The convert-fcrontab program in fcron 3.0.0 might allow local users to gain privileges via a long command-line argument, which causes Linux glibc to report heap memory corruption, possibly because a strcpy in the strdup2 function can \"overwrite some data.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:thibault_godouet:fcron:3.0.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 4.6
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 3.9,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-04T02:02Z",
    "lastModifiedDate" : "2018-10-19T15:45Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0540",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "tachyon",
            "product" : {
              "product_data" : [ {
                "product_name" : "vanilla_guestbook",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0_beta",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.evuln.com/vulns/54/summary.html",
          "name" : "http://www.evuln.com/vulns/54/summary.html",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/423957/100/0/threaded",
          "name" : "20060201 [eVuln] Vanilla Guestbook Multiple XSS & SQL Injection Vulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16464",
          "name" : "16464",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24412",
          "name" : "vanillaguestbook-messages-sql-injection(24412)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple SQL injection vulnerabilities in Tachyon Vanilla Guestbook 1.0 beta allow remote attackers to execute arbitrary SQL commands via unspecified vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tachyon:vanilla_guestbook:1.0_beta:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-04T02:02Z",
    "lastModifiedDate" : "2018-10-19T15:45Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0541",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "tachyon",
            "product" : {
              "product_data" : [ {
                "product_name" : "vanilla_guestbook",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0_beta",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.evuln.com/vulns/54/summary.html",
          "name" : "http://www.evuln.com/vulns/54/summary.html",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/423957/100/0/threaded",
          "name" : "20060201 [eVuln] Vanilla Guestbook Multiple XSS & SQL Injection Vulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/426200/100/0/threaded",
          "name" : "20060227 Re: [eVuln] Vanilla Guestbook Multiple XSS & SQL Injection Vulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16464",
          "name" : "16464",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24411",
          "name" : "vanillaguestbook-name-xss(24411)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple cross-site scripting (XSS) vulnerabilities in Tachyon Vanilla Guestbook 1.0 beta allow remote attackers to inject arbitrary web script or HTML via unknown vectors related to \"posting new messages.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tachyon:vanilla_guestbook:1.0_beta:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-04T02:02Z",
    "lastModifiedDate" : "2018-10-19T15:45Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0542",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "nukedweb",
            "product" : {
              "product_data" : [ {
                "product_name" : "guestbookhost",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2005-04-25",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18761",
          "name" : "18761",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.evuln.com/vulns/56/summary.html",
          "name" : "http://www.evuln.com/vulns/56/summary.html",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/424714/100/0/threaded",
          "name" : "20060209 [eVuln] GuestBookHost Authentication Bypass",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16545",
          "name" : "16545",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0465",
          "name" : "ADV-2006-0465",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24406",
          "name" : "guestbookhost-login-sql-injection(24406)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple SQL injection vulnerabilities in config.php in NukedWeb GuestBookHost 2005.04.25 allow remote attackers to execute arbitrary SQL commands via the (1) email and (2) password parameters."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:nukedweb:guestbookhost:2005-04-25:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-04T02:02Z",
    "lastModifiedDate" : "2018-10-19T15:45Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0543",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "cerulean_studios",
            "product" : {
              "product_data" : [ {
                "product_name" : "trillian",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.1.0.120",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.osvdb.org/22877",
          "name" : "22877",
          "refsource" : "OSVDB",
          "tags" : [ "Patch" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cerulean Trillian 3.1.0.120 allows remote attackers to cause a denial of service (client crash) via an AIM message containing the Mac encoded Rich Text Format (RTF) escape sequences (1) \\'d1, (2) \\'d2, (3) \\'d3, (4) \\'d4, and (5) \\'d5.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cerulean_studios:trillian:3.1.0.120:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-04T02:02Z",
    "lastModifiedDate" : "2008-09-05T20:59Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0544",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "ie",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/16463",
          "name" : "16463",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.security-protocols.com/advisory/sp-x23-advisory.txt",
          "name" : "http://www.security-protocols.com/advisory/sp-x23-advisory.txt",
          "refsource" : "MISC",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "urlmon.dll in Microsoft Internet Explorer 7.0 beta 2 (aka 7.0.5296.0) allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a BGSOUND element with its SRC attribute set to \"file://\" followed by a large number of \"-\" (dash of hyphen) characters."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:ie:7.0:beta_2:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-04T02:02Z",
    "lastModifiedDate" : "2008-09-05T20:59Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0545",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ubbcentral",
            "product" : {
              "product_data" : [ {
                "product_name" : "ubb.threads",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.2.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.2.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.2.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://archives.neohapsis.com/archives/bugtraq/2006-03/0494.html",
          "name" : "20060325 UBBThreads<=5.5.1+6.0.2+6.0 br5+6.0.1 SQL injection",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1015549",
          "name" : "1015549",
          "refsource" : "SECTRACK",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.cyberlords.net/advisories/cl_ubb.txt",
          "name" : "http://www.cyberlords.net/advisories/cl_ubb.txt",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/22808",
          "name" : "22808",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16520",
          "name" : "16520",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24381",
          "name" : "ubbthreads-showflat-sql-injection(24381)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in showflat.php in Groupee (formerly known as Infopop) UBB.threads 6.3 and earlier allows remote attackers to execute arbitrary SQL commands via the Number parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ubbcentral:ubb.threads:6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ubbcentral:ubb.threads:6.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ubbcentral:ubb.threads:6.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ubbcentral:ubb.threads:6.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ubbcentral:ubb.threads:6.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ubbcentral:ubb.threads:6.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ubbcentral:ubb.threads:6.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ubbcentral:ubb.threads:6.2.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ubbcentral:ubb.threads:6.2.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ubbcentral:ubb.threads:6.2.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ubbcentral:ubb.threads:6.3:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-04T02:02Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0546",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "egeinternet",
            "product" : {
              "product_data" : [ {
                "product_name" : "egeinternet",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/archive/1/423365/100/0/threaded",
          "name" : "20060128 Ege Internet Web Desing Remote Command Exucetion",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in index.php in a certain application available from /v1/tr/portfoy.php on www.egeinternet.com allows remote attackers to execute arbitrary code via \"evilcode\" in the key parameter, possibly a PHP remote file include vulnerability in which the attack vector is a URL in the key parameter.  NOTE: it is not clear whether this vulnerability is associated with an online service or application service provider.  If so, then it should not be included in CVE."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:egeinternet:egeinternet:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-04T02:02Z",
    "lastModifiedDate" : "2018-10-19T15:45Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0547",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "database_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.1.7.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.2.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.2.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.2.0.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.grok.org.uk/pipermail/full-disclosure/2006-January/041464.html",
          "name" : "20060117 Oracle DBMS - Access Control Bypass in Login",
          "refsource" : "FULLDISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.imperva.com/application_defense_center/papers/oracle-dbms-01172006.html",
          "name" : "http://www.imperva.com/application_defense_center/papers/oracle-dbms-01172006.html",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.integrigy.com/info/IntegrigySecurityAnalysis-CPU0106.pdf",
          "name" : "http://www.integrigy.com/info/IntegrigySecurityAnalysis-CPU0106.pdf",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/871756",
          "name" : "VU#871756",
          "refsource" : "CERT-VN",
          "tags" : [ "Third Party Advisory", "US Government Resource" ]
        }, {
          "url" : "http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html",
          "name" : "http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.red-database-security.com/advisory/oracle_cpu_jan_2006.html",
          "name" : "http://www.red-database-security.com/advisory/oracle_cpu_jan_2006.html",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA06-018A.html",
          "name" : "TA06-018A",
          "refsource" : "CERT",
          "tags" : [ "Third Party Advisory", "US Government Resource" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24184",
          "name" : "oracle-login-command-execute(24184)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Oracle Database 8i, 9i, and 10g allow remote authenticated users to execute arbitrary SQL statements in the context of the SYS user and bypass audit logging, including statements to create new privileged database accounts, via a modified AUTH_ALTER_SESSION attribute in the authentication phase of the Transparent Network Substrate (TNS) protocol.  NOTE: due to the lack of relevant details from the Oracle advisory, a separate CVE is being created since it cannot be conclusively proven that this issue has been addressed by Oracle.  It is possible that this is the same issue as Oracle Vuln# DB18 from the January 2006 CPU, in which case this would be subsumed by CVE-2006-0265."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database_server:8.1.7.4:r3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database_server:9.2.0.6:r2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database_server:9.2.0.7:r2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database_server:10.1.0.3:r1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database_server:10.1.0.4:r1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database_server:10.1.0.5:r1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database_server:10.2.0.1:r2:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-04T02:02Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0548",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "database_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.1.0.4.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.integrigy.com/info/IntegrigySecurityAnalysis-CPU0106.pdf",
          "name" : "http://www.integrigy.com/info/IntegrigySecurityAnalysis-CPU0106.pdf",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/150332",
          "name" : "VU#150332",
          "refsource" : "CERT-VN",
          "tags" : [ "Third Party Advisory", "US Government Resource" ]
        }, {
          "url" : "http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html",
          "name" : "http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.red-database-security.com/advisory/oracle_cpu_jan_2006.html",
          "name" : "http://www.red-database-security.com/advisory/oracle_cpu_jan_2006.html",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA06-018A.html",
          "name" : "TA06-018A",
          "refsource" : "CERT",
          "tags" : [ "Third Party Advisory", "US Government Resource" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24321",
          "name" : "oracle-january2006-update(24321)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in the Oracle Text component of Oracle Database 10g, and possibly earlier versions, might allow remote attackers to execute arbitrary SQL commands via unknown vectors. NOTE: due to the lack of relevant details from the Oracle advisory, a separate CVE is being created since it cannot be conclusively proven that this issue has been addressed by Oracle.  It is possible that this is the same issue as Oracle Vuln# DB15 from the January 2006 CPU, in which case this would be subsumed by CVE-2006-0260."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database_server:10.1.0.4.2:r1:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-04T02:02Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0549",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "database_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.1.0.5",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.integrigy.com/info/IntegrigySecurityAnalysis-CPU0106.pdf",
          "name" : "http://www.integrigy.com/info/IntegrigySecurityAnalysis-CPU0106.pdf",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/629316",
          "name" : "VU#629316",
          "refsource" : "CERT-VN",
          "tags" : [ "Third Party Advisory", "US Government Resource" ]
        }, {
          "url" : "http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html",
          "name" : "http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.red-database-security.com/advisory/oracle_cpu_jan_2006.html",
          "name" : "http://www.red-database-security.com/advisory/oracle_cpu_jan_2006.html",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.red-database-security.com/advisory/oracle_sql_injection_dbms_metadata_util.html",
          "name" : "http://www.red-database-security.com/advisory/oracle_sql_injection_dbms_metadata_util.html",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA06-018A.html",
          "name" : "TA06-018A",
          "refsource" : "CERT",
          "tags" : [ "Third Party Advisory", "US Government Resource" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24321",
          "name" : "oracle-january2006-update(24321)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in the SYS.DBMS_METADATA_UTIL package in Oracle Database 10g, and possibly earlier versions, might allow remote attackers to execute arbitrary SQL commands via unknown vectors. NOTE: due to the lack of relevant details from the Oracle advisory, a separate CVE is being created since it cannot be conclusively proven that this issue has been addressed by Oracle.  It is possible that this is the same issue as Oracle Vuln# DB05 from the January 2006 CPU, in which case this would be subsumed by CVE-2006-0260.  However, there are some inconsistencies that make this unclear, and there is also a possibility that this is related to DB06, which is subsumed by CVE-2006-0259."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database_server:10.1.0.5:r1:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-04T02:02Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0550",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "oracle_client",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.integrigy.com/info/IntegrigySecurityAnalysis-CPU0106.pdf",
          "name" : "http://www.integrigy.com/info/IntegrigySecurityAnalysis-CPU0106.pdf",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/999268",
          "name" : "VU#999268",
          "refsource" : "CERT-VN",
          "tags" : [ "Patch", "Third Party Advisory", "US Government Resource" ]
        }, {
          "url" : "http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html",
          "name" : "http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html",
          "refsource" : "MISC",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.red-database-security.com/advisory/oracle_cpu_jan_2006.html",
          "name" : "http://www.red-database-security.com/advisory/oracle_cpu_jan_2006.html",
          "refsource" : "MISC",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA06-018A.html",
          "name" : "TA06-018A",
          "refsource" : "CERT",
          "tags" : [ "Patch", "Third Party Advisory", "US Government Resource" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24321",
          "name" : "oracle-january2006-update(24321)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Buffer overflow in an unspecified Oracle Client utility might allow remote attackers to execute arbitrary code or cause a denial of service.  NOTE: due to the lack of relevant details from the Oracle advisory, a separate CVE is being created since it cannot be conclusively proven that this issue has been addressed by Oracle.  It is possible that this is the same issue as Oracle Vuln# DBC02 from the January 2006 CPU, in which case this would be a duplicate of CVE-2006-0283.  However, there are enough inconsistencies that the mapping can not be made authoritatively."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:oracle_client:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-04T02:02Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0551",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "database_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.1.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.2.0.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.integrigy.com/info/IntegrigySecurityAnalysis-CPU0106.pdf",
          "name" : "http://www.integrigy.com/info/IntegrigySecurityAnalysis-CPU0106.pdf",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/983340",
          "name" : "VU#983340",
          "refsource" : "CERT-VN",
          "tags" : [ "Patch", "Third Party Advisory", "US Government Resource" ]
        }, {
          "url" : "http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html",
          "name" : "http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html",
          "refsource" : "MISC",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.red-database-security.com/advisory/oracle_cpu_jan_2006.html",
          "name" : "http://www.red-database-security.com/advisory/oracle_cpu_jan_2006.html",
          "refsource" : "MISC",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA06-018A.html",
          "name" : "TA06-018A",
          "refsource" : "CERT",
          "tags" : [ "Patch", "Third Party Advisory", "US Government Resource" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24321",
          "name" : "oracle-january2006-update(24321)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in the Data Pump Metadata API in Oracle Database 10g and possibly earlier might allow remote attackers to execute arbitrary SQL commands via unknown vectors.  NOTE: due to the lack of relevant details from the Oracle advisory, a separate CVE is being created since it cannot be conclusively proven that this issue has been addressed by Oracle.  It is possible that this is the same issue as Oracle Vuln# DB06 from the January 2006 CPU, in which case this would be subsumed by CVE-2006-0259 or, if it is DB05, subsumed by CVE-2006-0260."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database_server:10.1.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database_server:10.1.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database_server:10.1.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database_server:10.2.0.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-04T02:02Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0552",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "10g_enterprise_manager_grid_control",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.1_.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1_.0.4",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "application_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0.2.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0.4.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0.4.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.2.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.2.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.2.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.2.1.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "collaboration_suite",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9.0.4.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "release_1",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "database_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.6.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.1.7.4",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "developer_suite",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9.0.2.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0.4.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0.4.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "e-business_suite",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11.5.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "11.5.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "11.5.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "11.5.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "11.5.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "11.5.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "11.5.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "11.5.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "11.5.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "11.5.10",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "enterpriseone",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.95.f1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "sp23_l1",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "oracle10g",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "enterprise_10.1.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "enterprise_10.1.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "personal_10.1.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "personal_10.1.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "standard_10.1.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "standard_10.1.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "standard_10.1.0.4.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "standard_10.1.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "standard_10.2.0.1",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "oracle8i",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "enterprise_8.1.7.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "standard_8.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "standard_8.0.6.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "standard_8.1.7.4",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "oracle9i",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "enterprise_9.0.1.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "enterprise_9.0.1.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "enterprise_9.0.1.5_fips",
                    "version_affected" : "="
                  }, {
                    "version_value" : "standard_9.2.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "standard_9.2.0.7",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "peoplesoft_enterprise_portal",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.9",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "workflow",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11.5.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "11.5.9.5",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18493",
          "name" : "18493",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://secunia.com/advisories/18608",
          "name" : "18608",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1015499",
          "name" : "1015499",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/545804",
          "name" : "VU#545804",
          "refsource" : "CERT-VN",
          "tags" : [ "Third Party Advisory", "US Government Resource" ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2006-082403.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2006-082403.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/22549",
          "name" : "22549",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16287",
          "name" : "16287",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0243",
          "name" : "ADV-2006-0243",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0323",
          "name" : "ADV-2006-0323",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24321",
          "name" : "oracle-january2006-update(24321)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Net Listener component of Oracle Database server 8.1.7.4, 9.0.1.5, 9.0.1.5 FIPS, and 9.2.0.7 has unspecified impact and attack vectors, as identified by Oracle Vuln# DB11."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:10g_enterprise_manager_grid_control:10.1_.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:10g_enterprise_manager_grid_control:10.1_.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_server:1.0.2.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_server:1.0.2.2:r1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_server:9.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_server:9.0.4.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_server:9.0.4.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_server:10.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_server:10.1.2.0.0:r2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_server:10.1.2.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_server:10.1.2.0.1:r2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_server:10.1.2.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_server:10.1.2.0.2:r2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_server:10.1.2.1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:collaboration_suite:9.0.4.2:r2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:collaboration_suite:10.1.1:r1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:collaboration_suite:10.1.2:r1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:collaboration_suite:release_1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database_server:8.0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database_server:8.0.6.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database_server:8.1.7.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:developer_suite:9.0.2.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:developer_suite:9.0.4.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:developer_suite:9.0.4.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:developer_suite:10.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:e-business_suite:11.5.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:e-business_suite:11.5.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:e-business_suite:11.5.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:e-business_suite:11.5.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:e-business_suite:11.5.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:e-business_suite:11.5.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:e-business_suite:11.5.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:e-business_suite:11.5.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:e-business_suite:11.5.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:e-business_suite:11.5.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:enterpriseone:8.95.f1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:enterpriseone:sp23_l1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:oracle10g:enterprise_10.1.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:oracle10g:enterprise_10.1.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:oracle10g:personal_10.1.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:oracle10g:personal_10.1.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:oracle10g:standard_10.1.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:oracle10g:standard_10.1.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:oracle10g:standard_10.1.0.4.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:oracle10g:standard_10.1.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:oracle10g:standard_10.2.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:oracle8i:enterprise_8.1.7.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:oracle8i:standard_8.0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:oracle8i:standard_8.0.6.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:oracle8i:standard_8.1.7.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:oracle9i:enterprise_9.0.1.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:oracle9i:enterprise_9.0.1.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:oracle9i:enterprise_9.0.1.5_fips:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:oracle9i:standard_9.2.0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:oracle9i:standard_9.2.0.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:peoplesoft_enterprise_portal:8.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:peoplesoft_enterprise_portal:8.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:peoplesoft_enterprise_portal:8.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:workflow:11.5.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:workflow:11.5.9.5:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-04T11:02Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0553",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "postgresql",
            "product" : {
              "product_data" : [ {
                "product_name" : "postgresql",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.1.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-264"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://archives.postgresql.org/pgsql-announce/2006-02/msg00008.php",
          "name" : "[pgsql-announce] 20060214 Minor Releases 7.3 thru 8.1 Available to Fix Security Issue",
          "refsource" : "MLIST",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18890",
          "name" : "18890",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1015636",
          "name" : "1015636",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/567452",
          "name" : "VU#567452",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.openpkg.org/security/OpenPKG-SA-2006.004-postgresql.html",
          "name" : "OpenPKG-SA-2006.004",
          "refsource" : "OPENPKG",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.postgresql.org/docs/8.1/static/release.html#RELEASE-8-1-3",
          "name" : "http://www.postgresql.org/docs/8.1/static/release.html#RELEASE-8-1-3",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/425037/100/0/threaded",
          "name" : "20060215 PostgreSQL security releases 8.1.3, 8.0.7, 7.4.12, 7.3.14",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16649",
          "name" : "16649",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0605",
          "name" : "ADV-2006-0605",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24718",
          "name" : "postgresql-setrole-privilege-elevation(24718)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "PostgreSQL 8.1.0 through 8.1.2 allows authenticated database users to gain additional privileges via \"knowledge of the backend protocol\" using a crafted SET ROLE to other database users, a different vulnerability than CVE-2006-0678."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:8.1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:8.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:8.1.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.5
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-14T19:06Z",
    "lastModifiedDate" : "2018-10-19T15:45Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0554",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "linux",
            "product" : {
              "product_data" : [ {
                "product_name" : "linux_kernel",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.8.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.8.1.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11_rc1_bk6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.12.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.12.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.12.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.12.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.12.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.12.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.13.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.13.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.13.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.13.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.14.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.14.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.14.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.14.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.15",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.15.5",
          "name" : "http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.15.5",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://secunia.com/advisories/19083",
          "name" : "19083",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/19220",
          "name" : "19220",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/20398",
          "name" : "20398",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/20914",
          "name" : "20914",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2006/dsa-1103",
          "name" : "DSA-1103",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDKSA-2006:059",
          "name" : "MDKSA-2006:059",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDKSA-2006:150",
          "name" : "MDKSA-2006:150",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.novell.com/linux/security/advisories/2006-05-31.html",
          "name" : "SUSE-SA:2006:028",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16921",
          "name" : "16921",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0804",
          "name" : "ADV-2006-0804",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/2554",
          "name" : "ADV-2006-2554",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24999",
          "name" : "kernel-ftruncate-information-disclosure(24999)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://usn.ubuntu.com/263-1/",
          "name" : "USN-263-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Linux kernel 2.6 before 2.6.15.5 allows local users to obtain sensitive information via a crafted XFS ftruncate call, which may return stale data."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.0:*:64-bit_x86:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.0:*:itanium_ia64_montecito:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.0:test1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.0:test10:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.0:test11:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.0:test2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.0:test3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.0:test4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.0:test5:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.0:test6:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.0:test7:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.0:test8:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.0:test9:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.1:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.1:rc2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.6:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.7:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.8:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.8:rc2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.8:rc3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.8.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.8.1.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.8.1.5:*:386:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.8.1.5:*:686:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.8.1.5:*:686_smp:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.8.1.5:*:amd64:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.8.1.5:*:amd64_k8:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.8.1.5:*:amd64_k8_smp:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.8.1.5:*:amd64_xeon:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.8.1.5:*:k7:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.8.1.5:*:k7_smp:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.8.1.5:*:power3:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.8.1.5:*:power3_smp:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.8.1.5:*:power4:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.8.1.5:*:power4_smp:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.8.1.5:*:powerpc:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.8.1.5:*:powerpc_smp:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.9:2.6.20:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.10:rc2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11:rc2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11:rc3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11:rc4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11.12:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11_rc1_bk6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.12:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.12:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.12:rc4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.12:rc5:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.12.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.12.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.12.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.12.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.12.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.12.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.13:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.13:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.13:rc4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.13:rc6:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.13:rc7:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.13.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.13.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.13.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.13.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.14:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.14:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.14:rc2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.14:rc3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.14:rc4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.14.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.14.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.14.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.14.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.15:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.15:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.15:rc3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.15:rc4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.15:rc5:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.15:rc6:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.15:rc7:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:S/C:N/I:P/A:N",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 1.7
        },
        "severity" : "LOW",
        "exploitabilityScore" : 3.1,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-03-07T02:02Z",
    "lastModifiedDate" : "2018-10-03T21:35Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0555",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "linux",
            "product" : {
              "product_data" : [ {
                "product_name" : "linux_kernel",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.8.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.8.1.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11_rc1_bk6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.12.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.12.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.12.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.12.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.12.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.12.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.13.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.13.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.13.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.13.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.14.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.14.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.14.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.14.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.15",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.15.5",
          "name" : "http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.15.5",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/19083",
          "name" : "19083",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/19108",
          "name" : "19108",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/19220",
          "name" : "19220",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/20237",
          "name" : "20237",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/20398",
          "name" : "20398",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/20914",
          "name" : "20914",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/21745",
          "name" : "21745",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://support.avaya.com/elmodocs2/security/ASA-2006-161.htm",
          "name" : "http://support.avaya.com/elmodocs2/security/ASA-2006-161.htm",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2006/dsa-1103",
          "name" : "DSA-1103",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDKSA-2006:059",
          "name" : "MDKSA-2006:059",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.novell.com/linux/security/advisories/2006-05-31.html",
          "name" : "SUSE-SA:2006:028",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/archives/fedora-announce-list/2006-March/msg00003.html",
          "name" : "FEDORA-2006-131",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2006-0493.html",
          "name" : "RHSA-2006:0493",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16922",
          "name" : "16922",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0804",
          "name" : "ADV-2006-0804",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/2554",
          "name" : "ADV-2006-2554",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/25000",
          "name" : "kernel-odirect-dos(25000)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9932",
          "name" : "oval:org.mitre.oval:def:9932",
          "refsource" : "OVAL",
          "tags" : [ ]
        }, {
          "url" : "https://usn.ubuntu.com/263-1/",
          "name" : "USN-263-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The Linux Kernel before 2.6.15.5 allows local users to cause a denial of service (NFS client panic) via unknown attack vectors related to the use of O_DIRECT (direct I/O)."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.0:*:64-bit_x86:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.0:*:itanium_ia64_montecito:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.0:test1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.0:test10:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.0:test11:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.0:test2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.0:test3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.0:test4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.0:test5:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.0:test6:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.0:test7:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.0:test8:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.0:test9:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.1:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.1:rc2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.6:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.7:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.8:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.8:rc2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.8:rc3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.8.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.8.1.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.8.1.5:*:386:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.8.1.5:*:686:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.8.1.5:*:686_smp:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.8.1.5:*:amd64:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.8.1.5:*:amd64_k8:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.8.1.5:*:amd64_k8_smp:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.8.1.5:*:amd64_xeon:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.8.1.5:*:k7:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.8.1.5:*:k7_smp:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.8.1.5:*:power3:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.8.1.5:*:power3_smp:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.8.1.5:*:power4:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.8.1.5:*:power4_smp:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.8.1.5:*:powerpc:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.8.1.5:*:powerpc_smp:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.9:2.6.20:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.10:rc2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11:rc2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11:rc3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11:rc4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11.12:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11_rc1_bk6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.12:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.12:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.12:rc4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.12:rc5:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.12.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.12.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.12.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.12.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.12.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.12.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.13:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.13:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.13:rc4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.13:rc6:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.13:rc7:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.13.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.13.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.13.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.13.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.14:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.14:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.14:rc2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.14:rc3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.14:rc4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.14.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.14.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.14.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.14.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.15:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.15:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.15:rc3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.15:rc4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.15:rc5:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.15:rc6:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.15:rc7:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 2.1
        },
        "severity" : "LOW",
        "exploitabilityScore" : 3.9,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-03-07T02:02Z",
    "lastModifiedDate" : "2018-10-03T21:35Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0556",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ ]
        } ]
      },
      "references" : {
        "reference_data" : [ ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "** REJECT **  DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2006. Notes: none."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ ]
    },
    "impact" : { },
    "publishedDate" : "2017-05-11T14:29Z",
    "lastModifiedDate" : "2017-05-11T14:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0557",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "linux",
            "product" : {
              "product_data" : [ {
                "product_name" : "linux_kernel",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.8.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.12.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.12.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.12.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.12.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.12.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.12.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.13.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.13.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.13.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.13.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.13.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.14.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.14.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.14.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.14.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.14.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.14.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.14.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.15.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.15.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.15.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.15.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.15.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.15.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.15.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.16",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lkml.org/lkml/2006/2/27/355",
          "name" : "http://lkml.org/lkml/2006/2/27/355",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHBA-2007-0304.html",
          "name" : "RHBA-2007-0304",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/19955",
          "name" : "19955",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/20398",
          "name" : "20398",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/20914",
          "name" : "20914",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1015752",
          "name" : "1015752",
          "refsource" : "SECTRACK",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.debian.org/security/2006/dsa-1103",
          "name" : "DSA-1103",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=636f13c174dd7c84a437d3c3e8fa66f03f7fda63",
          "name" : "http://www.kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=636f13c174dd7c84a437d3c3e8fa66f03f7fda63",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commitdiff;h=636f13c174dd7c84a437d3c3e8fa66f03f7fda63",
          "name" : "http://www.kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commitdiff;h=636f13c174dd7c84a437d3c3e8fa66f03f7fda63",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDKSA-2006:059",
          "name" : "MDKSA-2006:059",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.novell.com/linux/security/advisories/2006-05-31.html",
          "name" : "SUSE-SA:2006:028",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/23895",
          "name" : "23895",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16924",
          "name" : "16924",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/2554",
          "name" : "ADV-2006-2554",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=184510",
          "name" : "https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=184510",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/25204",
          "name" : "linux-get-nodes-dos(25204)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9674",
          "name" : "oval:org.mitre.oval:def:9674",
          "refsource" : "OVAL",
          "tags" : [ ]
        }, {
          "url" : "https://usn.ubuntu.com/281-1/",
          "name" : "USN-281-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "sys_mbind in mempolicy.c in Linux kernel 2.6.16 and earlier does not sanity check the maxnod variable before making certain computations for the get_nodes function, which has unknown impact and attack vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.1:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.1:rc2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.1:rc3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.2:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.2:rc2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.2:rc3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.3:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.3:rc2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.3:rc3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.3:rc4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.4:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.4:rc2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.4:rc3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.5:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.5:rc2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.5:rc3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.6:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.6:rc2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.6:rc3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.7:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.7:rc2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.7:rc3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.8:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.8:rc2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.8:rc3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.8:rc4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.8.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.9:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.9:rc2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.9:rc3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.9:rc4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.10:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.10:rc2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.10:rc3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11:rc2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11:rc3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11:rc4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11:rc5:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11.12:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.12:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.12:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.12:rc2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.12:rc3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.12:rc4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.12:rc5:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.12:rc6:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.12.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.12.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.12.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.12.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.12.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.12.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.13:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.13:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.13:rc2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.13:rc3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.13:rc4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.13:rc5:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.13:rc6:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.13:rc7:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.13.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.13.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.13.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.13.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.13.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.14:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.14:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.14:rc2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.14:rc3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.14:rc4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.14:rc5:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.14.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.14.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.14.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.14.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.14.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.14.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.14.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.15:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.15:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.15:rc2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.15:rc3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.15:rc4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.15:rc5:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.15:rc6:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.15:rc7:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.15.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.15.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.15.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.15.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.15.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.15.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.15.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "2.6.16"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16:rc2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16:rc3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16:rc4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16:rc5:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16:rc6:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:N/I:N/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 4.9
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 3.9,
        "impactScore" : 6.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-03-12T21:02Z",
    "lastModifiedDate" : "2018-10-03T21:35Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0558",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "linux",
            "product" : {
              "product_data" : [ {
                "product_name" : "linux_kernel",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.12.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.12.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.12.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.12.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.12.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.12.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.13.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.13.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.13.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.13.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.14.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.14.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.14.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.14.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.14.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.15.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.15.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.15.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.15.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.15.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.16",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.16.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6_test9_cvs",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://marc.info/?l=linux-ia64&m=113882384921688",
          "name" : "[linux-ia64] [PATCH 1/1] ia64: perfmon.c trips BUG_ON in put_page_testzero",
          "refsource" : "MLIST",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/19737",
          "name" : "19737",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/20914",
          "name" : "20914",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/26709",
          "name" : "26709",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2006/dsa-1103",
          "name" : "DSA-1103",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2007-0774.html",
          "name" : "RHSA-2007:0774",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/17482",
          "name" : "17482",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/1444",
          "name" : "ADV-2006-1444",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/2554",
          "name" : "ADV-2006-2554",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=185082",
          "name" : "https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=185082",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10177",
          "name" : "oval:org.mitre.oval:def:10177",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "perfmon (perfmon.c) in Linux kernel on IA64 architectures allows local users to cause a denial of service (crash) by interrupting a task while another process is accessing the mm_struct, which triggers a BUG_ON action in the put_page_testzero function."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.0:test1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.0:test10:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.0:test11:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.0:test2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.0:test3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.0:test4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.0:test5:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.0:test6:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.0:test7:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.0:test8:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.0:test9:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.1:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.1:rc2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.6:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.7:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.8:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.8:rc2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.8:rc3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.9:2.6.20:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.10:rc2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11:rc2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11:rc3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11:rc4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11.12:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.12:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.12:rc4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.12:rc5:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.12.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.12.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.12.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.12.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.12.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.12.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.13:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.13:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.13:rc4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.13:rc6:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.13:rc7:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.13.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.13.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.13.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.13.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.14:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.14:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.14:rc2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.14:rc3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.14:rc4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.14.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.14.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.14.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.14.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.14.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.15:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.15:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.15:rc3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.15.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.15.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.15.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.15.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.15.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6_test9_cvs:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:N/I:N/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 4.9
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 3.9,
        "impactScore" : 6.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-04-14T21:02Z",
    "lastModifiedDate" : "2017-10-11T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0559",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "mcafee",
            "product" : {
              "product_data" : [ {
                "product_name" : "webshield_smtp",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.5",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/19491",
          "name" : "19491",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/671",
          "name" : "671",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1015861",
          "name" : "1015861",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/24366",
          "name" : "24366",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/429812/100/0/threaded",
          "name" : "20060404 SYMSA-2006-002: McAfee WebShield SMTP Format String Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16742",
          "name" : "16742",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/1219",
          "name" : "ADV-2006-1219",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/25621",
          "name" : "webshield-smtp-format-string(25621)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Format string vulnerability in the SMTP server for McAfee WebShield 4.5 MR2 and earlier allows remote attackers to execute arbitrary code via format strings in the domain name portion of a destination address, which are not properly handled when a bounce message is constructed."
        }, {
          "lang" : "en",
          "value" : "The vendor has released a patch (P0803), along with version 4.5 MR2 to address this issue."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mcafee:webshield_smtp:*:mr2_patch:*:*:*:*:*:*",
          "versionEndIncluding" : "4.5"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-04-04T14:04Z",
    "lastModifiedDate" : "2018-10-19T15:45Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0560",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ ]
        } ]
      },
      "references" : {
        "reference_data" : [ ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "** REJECT **  DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2006. Notes: none."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ ]
    },
    "impact" : { },
    "publishedDate" : "2017-05-11T14:29Z",
    "lastModifiedDate" : "2017-05-11T14:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0561",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "cisco",
            "product" : {
              "product_data" : [ {
                "product_name" : "secure_access_control_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://securitytracker.com/id?1016042",
          "name" : "1016042",
          "refsource" : "SECTRACK",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.cisco.com/warp/public/707/cisco-sr-20060508-acs.shtml",
          "name" : "20060508 Response to Symantec SYMSA-2006-003 Cisco Secure ACS for Windows - Administrator Password Disclosure",
          "refsource" : "CISCO",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.osvdb.org/25892",
          "name" : "25892",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/433286/100/0/threaded",
          "name" : "20060508 SYMSA-2006-003: Cisco Secure ACS for Windows - Administrator Password Disclosure",
          "refsource" : "BUGTRAQ",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/433301/100/0/threaded",
          "name" : "20060508 Re: SYMSA-2006-003: Cisco Secure ACS for Windows - Administrator Password Disclosure",
          "refsource" : "BUGTRAQ",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16743",
          "name" : "16743",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.symantec.com/enterprise/research/SYMSA-2006-003.txt",
          "name" : "http://www.symantec.com/enterprise/research/SYMSA-2006-003.txt",
          "refsource" : "MISC",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/1741",
          "name" : "ADV-2006-1741",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/26307",
          "name" : "cisco-acs-admin-password-disclosure(26307)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cisco Secure Access Control Server (ACS) 3.x for Windows stores ACS administrator passwords and the master key in the registry with insecure permissions, which allows local users and remote administrators to decrypt the passwords by using Microsoft's cryptographic API functions to obtain the plaintext version of the master key."
        }, {
          "lang" : "en",
          "value" : "This vulnerability is addressed in the following product release:\r\nCisco, Secure Access Control Server, 4.0.1"
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cisco:secure_access_control_server:3.0:*:windows_nt:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cisco:secure_access_control_server:3.0.1:*:windows_nt:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cisco:secure_access_control_server:3.0.3:*:windows_nt:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cisco:secure_access_control_server:3.1:*:windows_nt:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cisco:secure_access_control_server:3.1.1:*:windows_nt:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cisco:secure_access_control_server:3.2:*:windows_nt:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cisco:secure_access_control_server:3.2:*:windows_server:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cisco:secure_access_control_server:3.3:*:windows_nt:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.2
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 3.9,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-05-10T02:14Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0562",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "pluggedout",
            "product" : {
              "product_data" : [ {
                "product_name" : "pluggedout_blog",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.9.9c",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://attrition.org/pipermail/vim/2006-February/000530.html",
          "name" : "20060206 VERIFY Pluggedout Blog 1.9.9c problem.php XSS",
          "refsource" : "VIM",
          "tags" : [ ]
        }, {
          "url" : "http://hamid.ir/security/pluggedoutblog.txt",
          "name" : "http://hamid.ir/security/pluggedoutblog.txt",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://secunia.com/advisories/18726",
          "name" : "18726",
          "refsource" : "SECUNIA",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1015586",
          "name" : "1015586",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/22927",
          "name" : "22927",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/423948/100/0/threaded",
          "name" : "20060204 PluggedOut Blog SQL injection and XSS",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0440",
          "name" : "ADV-2006-0440",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24482",
          "name" : "pluggedoutblog-problem-xss(24482)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in problem.php in PluggedOut Blog 1.9.9c allows remote attackers to inject arbitrary web script or HTML via the data parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pluggedout:pluggedout_blog:1.9.9c:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-06T23:02Z",
    "lastModifiedDate" : "2018-10-19T15:45Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0563",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "pluggedout",
            "product" : {
              "product_data" : [ {
                "product_name" : "pluggedout_blog",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.9.9c",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://attrition.org/pipermail/vim/2006-February/000531.html",
          "name" : "20060206 VERIFY Pluggedout Blog 1.9.9c exec.php SQL injection",
          "refsource" : "VIM",
          "tags" : [ ]
        }, {
          "url" : "http://hamid.ir/security/pluggedoutblog.txt",
          "name" : "http://hamid.ir/security/pluggedoutblog.txt",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://secunia.com/advisories/18726",
          "name" : "18726",
          "refsource" : "SECUNIA",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/415",
          "name" : "415",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1015586",
          "name" : "1015586",
          "refsource" : "SECTRACK",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.osvdb.org/22926",
          "name" : "22926",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/423948/100/0/threaded",
          "name" : "20060204 PluggedOut Blog SQL injection and XSS",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0440",
          "name" : "ADV-2006-0440",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24480",
          "name" : "pluggedoutblog-exec-sql-injection(24480)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in exec.php in PluggedOut Blog 1.9.9c allows remote attackers to execute arbitrary SQL commands via the entryid parameter in a comment_add action."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pluggedout:pluggedout_blog:1.9.9c:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-06T23:02Z",
    "lastModifiedDate" : "2018-10-19T15:45Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0564",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "html_help",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.4",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "html_help_workshop",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.74.8702.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18740",
          "name" : "18740",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1015585",
          "name" : "1015585",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://users.pandora.be/bratax/advisories/b008.html",
          "name" : "http://users.pandora.be/bratax/advisories/b008.html",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/124460",
          "name" : "VU#124460",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.osvdb.org/22941",
          "name" : "22941",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0446",
          "name" : "ADV-2006-0446",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24481",
          "name" : "mshtmlhelp-workshop-hhp-bo(24481)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Stack-based buffer overflow in Microsoft HTML Help Workshop 4.74.8702.0, and possibly earlier versions, and as included in the Microsoft HTML Help 1.4 SDK, allows context-dependent attackers to execute arbitrary code via a .hhp file with a long Contents file field."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:html_help:1.4:*:sdk:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:html_help_workshop:4.74.8702.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-06T23:02Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0565",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "gerrit_van_aaken",
            "product" : {
              "product_data" : [ {
                "product_name" : "loudblog",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.4",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-94"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://retrogod.altervista.org/loudblog_04_incl_xpl.html",
          "name" : "http://retrogod.altervista.org/loudblog_04_incl_xpl.html",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://secunia.com/advisories/18722",
          "name" : "18722",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/410",
          "name" : "410",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/556",
          "name" : "556",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1015583",
          "name" : "1015583",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/22921",
          "name" : "22921",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/423947/100/0/threaded",
          "name" : "20060204 LoudBlog <= 0.4 arbitrary remote inclusion",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16495",
          "name" : "16495",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0441",
          "name" : "ADV-2006-0441",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24479",
          "name" : "loudblog-backendsettings-file-include(24479)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "PHP remote file include vulnerability in inc/backend_settings.php in Loudblog 0.4 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the $GLOBALS[path] parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:gerrit_van_aaken:loudblog:0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:gerrit_van_aaken:loudblog:0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:gerrit_van_aaken:loudblog:0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:gerrit_van_aaken:loudblog:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "0.4"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-06T23:02Z",
    "lastModifiedDate" : "2018-10-19T15:45Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0566",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "communigate",
            "product" : {
              "product_data" : [ {
                "product_name" : "communigate_pro_core_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.0.7",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18701",
          "name" : "18701",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/416",
          "name" : "416",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1015587",
          "name" : "1015587",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.gleg.net/advisory_cg2.shtml",
          "name" : "http://www.gleg.net/advisory_cg2.shtml",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/22932",
          "name" : "22932",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/423968/100/0/threaded",
          "name" : "20060204 ProtoVer LDAP vs CommuniGate Pro 5.0.7",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.stalker.com/CommuniGatePro/History.html",
          "name" : "http://www.stalker.com/CommuniGatePro/History.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0444",
          "name" : "ADV-2006-0444",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24409",
          "name" : "communigate-ldap-bo(24409)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The LDAP component in CommuniGate Pro Core Server 5.0.7 allows remote attackers to cause a denial of service (application crash) via LDAP messages that contain Distinguished Names (DN) fields with a large number of elements."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:communigate:communigate_pro_core_server:5.0.7:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-06T23:02Z",
    "lastModifiedDate" : "2018-10-19T15:45Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0567",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "curtis_farnham",
            "product" : {
              "product_data" : [ {
                "product_name" : "files_xaraya_module",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.3.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.4.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.vupen.com/english/advisories/2006/0371",
          "name" : "ADV-2006-0371",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://xaraya.curtisfarnham.com/articles/Files_0.5.1_-_Security_Fix_and_other_things",
          "name" : "http://xaraya.curtisfarnham.com/articles/Files_0.5.1_-_Security_Fix_and_other_things",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24393",
          "name" : "files-archive-directory-directory-traversal(24393)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Directory traversal vulnerability in Files Xaraya module before 0.5.1, when the Archive Directory field on the Modify Config page is blank, allows remote attackers to access files outside of the web root via \"..\" (dot dot) sequences."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:curtis_farnham:files_xaraya_module:0.3.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:curtis_farnham:files_xaraya_module:0.4.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-07T18:06Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0568",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "outblaze",
            "product" : {
              "product_data" : [ {
                "product_name" : "outblaze",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://archives.neohapsis.com/archives/fulldisclosure/2006-02/0024.html",
          "name" : "20060202 Outblaze Cross Site Scripting Vulnerability",
          "refsource" : "FULLDISC",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18710",
          "name" : "18710",
          "refsource" : "SECUNIA",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/411",
          "name" : "411",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.morx.org/outblazeXSS.txt",
          "name" : "http://www.morx.org/outblazeXSS.txt",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/22909",
          "name" : "22909",
          "refsource" : "OSVDB",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/423915/100/0/threaded",
          "name" : "20060203 Outblaze Cross Site Scripting Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0439",
          "name" : "ADV-2006-0439",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24476",
          "name" : "outblaze-email-thrownmain-xss(24476)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in throw.main in Outblaze allows remote attackers to inject arbitrary web script or HTML via the file parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:outblaze:outblaze:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-07T18:06Z",
    "lastModifiedDate" : "2018-10-19T15:45Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0569",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "papoo",
            "product" : {
              "product_data" : [ {
                "product_name" : "papoo",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.1.4",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18721",
          "name" : "18721",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/22913",
          "name" : "22913",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0438",
          "name" : "ADV-2006-0438",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24500",
          "name" : "papoo-username-xss(24500)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in user_class.php in Papoo 2.1.4 and earlier allows remote attackers to inject arbitrary web script or HTML via the username field during the registration of a new account.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:papoo:papoo:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "2.1.4"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-07T18:06Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0570",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "hinton_design",
            "product" : {
              "product_data" : [ {
                "product_name" : "phpstatus",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://evuln.com/vulns/61/summary.html",
          "name" : "http://evuln.com/vulns/61/summary.html",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18791",
          "name" : "18791",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/427",
          "name" : "427",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/424842/100/0/threaded",
          "name" : "20060212 [eVuln] phpstatus Authentication Bypass",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16587",
          "name" : "16587",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0450",
          "name" : "ADV-2006-0450",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple SQL injection vulnerabilities in phpstatus 1.0, when gpc_magic_quotes is disabled, allow remote attackers to execute arbitrary SQL commands and bypass authentication via (1) the username parameter in check.php and (2) unknown attack vectors in the administrative interface."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hinton_design:phpstatus:1.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-07T18:06Z",
    "lastModifiedDate" : "2018-10-19T15:45Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0571",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "hinton_design",
            "product" : {
              "product_data" : [ {
                "product_name" : "phpstatus",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://evuln.com/vulns/61/summary.html",
          "name" : "http://evuln.com/vulns/61/summary.html",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18791",
          "name" : "18791",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/427",
          "name" : "427",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/424842/100/0/threaded",
          "name" : "20060212 [eVuln] phpstatus Authentication Bypass",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16587",
          "name" : "16587",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0450",
          "name" : "ADV-2006-0450",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple cross-site scripting (XSS) vulnerabilities in phpstatus 1.0 allow remote attackers to inject arbitrary web script or HTML via unknown attack vectors in the administrative interface."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hinton_design:phpstatus:1.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-07T18:06Z",
    "lastModifiedDate" : "2018-10-19T15:45Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0572",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "hinton_design",
            "product" : {
              "product_data" : [ {
                "product_name" : "phpstatus",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://evuln.com/vulns/61/summary.html",
          "name" : "http://evuln.com/vulns/61/summary.html",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18791",
          "name" : "18791",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/427",
          "name" : "427",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/424842/100/0/threaded",
          "name" : "20060212 [eVuln] phpstatus Authentication Bypass",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16587",
          "name" : "16587",
          "refsource" : "BID",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "phpstatus 1.0 does not require passwords when using cookies to identify a user, which allows remote attackers to bypass authentication."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hinton_design:phpstatus:1.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-07T18:06Z",
    "lastModifiedDate" : "2018-10-19T15:45Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0573",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "cpanel",
            "product" : {
              "product_data" : [ {
                "product_name" : "cpanel",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.4.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.4.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.4.2_stable_48",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://archives.neohapsis.com/archives/fulldisclosure/2006-02/0025.html",
          "name" : "20060202 cPanel Multiple Cross Site Scripting Vulnerability",
          "refsource" : "FULLDISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://marc.info/?l=bugtraq&m=113898556313924&w=2",
          "name" : "20060203 cPanel Multiple Cross Site Scripting Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18695",
          "name" : "18695",
          "refsource" : "SECUNIA",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/22936",
          "name" : "22936",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/22937",
          "name" : "22937",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/22938",
          "name" : "22938",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/22939",
          "name" : "22939",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0433",
          "name" : "ADV-2006-0433",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24468",
          "name" : "cpanel-scripts-xss(24468)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple cross-site scripting (XSS) vulnerabilies in cPanel 10 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) email parameter to (a) editquota.html or (b) dodelpop.html; (2) showtree parameter to (c) diskusage.html; or the (3) mon, (4) year, (5) target, or (6) domain parameter to (d) stats/detailbw.html."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cpanel:cpanel:5.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cpanel:cpanel:5.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cpanel:cpanel:6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cpanel:cpanel:6.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cpanel:cpanel:6.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cpanel:cpanel:6.4.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cpanel:cpanel:6.4.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cpanel:cpanel:6.4.2_stable_48:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cpanel:cpanel:7.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cpanel:cpanel:8.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cpanel:cpanel:9.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cpanel:cpanel:9.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cpanel:cpanel:10:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-07T18:06Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0574",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "cpanel",
            "product" : {
              "product_data" : [ {
                "product_name" : "cpanel",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://archives.neohapsis.com/archives/fulldisclosure/2006-02/0062.html",
          "name" : "20060204 cPanel 10 mime/handle.html XSS Vulnerability",
          "refsource" : "FULLDISC",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18695",
          "name" : "18695",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1015589",
          "name" : "1015589",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/22940",
          "name" : "22940",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/424148/100/0/threaded",
          "name" : "20060205 cPanel 10 handle.html XSS Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0433",
          "name" : "ADV-2006-0433",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in mime/handle.html in cPanel 10 allows remote attackers to inject arbitrary web script or HTML via the (1) file extension or (2) mime-type."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cpanel:cpanel:10:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-07T18:06Z",
    "lastModifiedDate" : "2018-10-19T15:45Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0575",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "thibault_godouet",
            "product" : {
              "product_data" : [ {
                "product_name" : "fcron",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.9.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://marc.info/?l=full-disclosure&m=113890734603201&w=2",
          "name" : "20060202 Re: Fcrontab - memory corruption on heap.",
          "refsource" : "FULLDISC",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18719",
          "name" : "18719",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/22905",
          "name" : "22905",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/25693",
          "name" : "25693",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.trustix.org/errata/2006/0006",
          "name" : "2006-0006",
          "refsource" : "TRUSTIX",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0435",
          "name" : "ADV-2006-0435",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24504",
          "name" : "fcron-dotdot-directory-traversal(24504)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "convert-fcrontab in Fcron 2.9.5 and 3.0.0 allows remote attackers to create or overwrite arbitrary files via \"..\" sequences and a symlink attack on the temporary file that is used during conversion."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:thibault_godouet:fcron:2.9.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:thibault_godouet:fcron:3.0.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-07T20:02Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0576",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "maynard_johnson",
            "product" : {
              "product_data" : [ {
                "product_name" : "oprofile",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.5.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.5.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.5.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.5.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.6.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.7.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.9.1",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.redhat.com/magazine/012oct05/features/oprofile/",
          "name" : "http://www.redhat.com/magazine/012oct05/features/oprofile/",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/424325/100/0/threaded",
          "name" : "20060207 Arbitrary code execution via OProfile",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16536",
          "name" : "16536",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10890",
          "name" : "oval:org.mitre.oval:def:10890",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Untrusted search path vulnerability in opcontrol in OProfile 0.9.1 and earlier allows local users to execute arbitrary commands via a modified PATH that references malicious (1) which or (2) dirname programs.  NOTE: while opcontrol normally is not run setuid, a common configuration suggests accessing opcontrol using sudo.  In such a context, this is a vulnerability."
        }, {
          "lang" : "en",
          "value" : "Per: http://cwe.mitre.org/data/definitions/426.html\r\n\r\n'CWE-426: Untrusted Search Path'"
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:maynard_johnson:oprofile:0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:maynard_johnson:oprofile:0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:maynard_johnson:oprofile:0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:maynard_johnson:oprofile:0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:maynard_johnson:oprofile:0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:maynard_johnson:oprofile:0.5.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:maynard_johnson:oprofile:0.5.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:maynard_johnson:oprofile:0.5.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:maynard_johnson:oprofile:0.5.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:maynard_johnson:oprofile:0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:maynard_johnson:oprofile:0.6.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:maynard_johnson:oprofile:0.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:maynard_johnson:oprofile:0.7.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:maynard_johnson:oprofile:0.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:maynard_johnson:oprofile:0.8.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:maynard_johnson:oprofile:0.8.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:maynard_johnson:oprofile:0.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:maynard_johnson:oprofile:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "0.9.1"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.2
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 3.9,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-08T00:06Z",
    "lastModifiedDate" : "2018-10-19T15:45Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0577",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "lexmark",
            "product" : {
              "product_data" : [ {
                "product_name" : "x1185",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18728",
          "name" : "18728",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/424322/100/0/threaded",
          "name" : "20060207 Re: High Risk Vulnerability in Lexmark Printer Sharing Service",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16534",
          "name" : "16534",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0482",
          "name" : "ADV-2006-0482",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24596",
          "name" : "lexmark-x1185-privilege-elevation(24596)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Lexmark X1185 printer allows local users to gain SYSTEM privileges by navigating to the \"Appearance\" dialog and selecting the \"Additional styles (skins) are available on the Lexmark web site\" option, which launches a web browser that is running with SYSTEM privileges."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:lexmark:x1185:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.2
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 3.9,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-08T00:06Z",
    "lastModifiedDate" : "2018-10-19T15:45Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0578",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "bluecoat",
            "product" : {
              "product_data" : [ {
                "product_name" : "sgos",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.1.2.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18622",
          "name" : "18622",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1015644",
          "name" : "1015644",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.bluecoat.com/support/knowledge/advisory_connect_denial_ignore.html",
          "name" : "http://www.bluecoat.com/support/knowledge/advisory_connect_denial_ignore.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/22853",
          "name" : "22853",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.secumind.net/content/french/modules/news/article.php?storyid=8",
          "name" : "http://www.secumind.net/content/french/modules/news/article.php?storyid=8",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0401",
          "name" : "ADV-2006-0401",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24446",
          "name" : "proxysg-connect-bypass-security(24446)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Blue Coat Proxy Security Gateway OS (SGOS) 4.1.2.1 does not enforce CONNECT rules when using Deep Content Inspection, which allows remote attackers to bypass connection filters."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:bluecoat:sgos:4.1.2.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-08T01:02Z",
    "lastModifiedDate" : "2018-10-30T16:25Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0579",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "mplayer",
            "product" : {
              "product_data" : [ {
                "product_name" : "mplayer",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0_pre7try2",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18718",
          "name" : "18718",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/19114",
          "name" : "19114",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.gentoo.org/security/en/glsa/glsa-200603-03.xml",
          "name" : "GLSA-200603-03",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDKSA-2006:048",
          "name" : "MDKSA-2006:048",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0457",
          "name" : "ADV-2006-0457",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24531",
          "name" : "mplayer-asf-integer-overflow(24531)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple integer overflows in (1) the new_demux_packet function in demuxer.h and (2) the demux_asf_read_packet function in demux_asf.c in MPlayer 1.0pre7try2 and earlier allow remote attackers to execute arbitrary code via an ASF file with a large packet length value. NOTE: the provenance of this information is unknown; portions of the details are obtained from third party information."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mplayer:mplayer:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.0_pre7try2"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-08T01:02Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0580",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "lotus_domino_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.immunitysec.com/pipermail/dailydave/2006-February/002896.html",
          "name" : "[Dailydave] 20060203 ProtoVer vs Lotus Domino Server 7.0",
          "refsource" : "MLIST",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18738",
          "name" : "18738",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1015592",
          "name" : "1015592",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16523",
          "name" : "16523",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0458",
          "name" : "ADV-2006-0458",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24518",
          "name" : "lotus-domino-ldap-dos(24518)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "IBM Lotus Domino Server 7.0 allows remote attackers to cause a denial of service (segmentation fault) via a crafted packet to the LDAP port (389/TCP)."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:lotus_domino_server:7.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-08T01:02Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0581",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "hosting_controller",
            "product" : {
              "product_data" : [ {
                "product_name" : "hosting_controller",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.1_hotfix_2.8",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18731",
          "name" : "18731",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1015584",
          "name" : "1015584",
          "refsource" : "SECTRACK",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.osvdb.org/22982",
          "name" : "22982",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/22983",
          "name" : "22983",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0460",
          "name" : "ADV-2006-0460",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24537",
          "name" : "hosting-controller-sql-injection(24537)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in Hosting Controller 6.1 Hotfix 2.8 allows remote authenticated users to execute arbitrary SQL commands via the (1) GatewayID parameter in an add action in AddGatewaySettings.asp and (2) IP parameter in IPManager.asp."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hosting_controller:hosting_controller:6.1_hotfix_2.8:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.5
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-08T01:02Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0582",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "kth",
            "product" : {
              "product_data" : [ {
                "product_name" : "heimdal",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.6.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.6.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.6.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.6.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.6.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.7.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.7.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.7.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.7.1.3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18733",
          "name" : "18733",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18806",
          "name" : "18806",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18894",
          "name" : "18894",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/19005",
          "name" : "19005",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/19302",
          "name" : "19302",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1015591",
          "name" : "1015591",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2006/dsa-977",
          "name" : "DSA-977",
          "refsource" : "DEBIAN",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.gentoo.org/security/en/glsa/glsa-200603-14.xml",
          "name" : "GLSA-200603-14",
          "refsource" : "GENTOO",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/22986",
          "name" : "22986",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.pdc.kth.se/heimdal/advisory/2006-02-06/",
          "name" : "http://www.pdc.kth.se/heimdal/advisory/2006-02-06/",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/426043/100/0/threaded",
          "name" : "SUSE-SA:2006:011",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16524",
          "name" : "16524",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.stacken.kth.se/lists/heimdal-discuss/2006-02/msg00028.html",
          "name" : "[heimdal-discuss] 20060206 Heimdal 0.7.2 and 0.6.6",
          "refsource" : "MLIST",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/usn-253-1",
          "name" : "USN-253-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0456",
          "name" : "ADV-2006-0456",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0628",
          "name" : "ADV-2006-0628",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24532",
          "name" : "heimdal-rshd-privilege-elevation(24532)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://usn.ubuntu.com/247-1/",
          "name" : "USN-247-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in rshd in Heimdal 0.6.x before 0.6.6 and 0.7.x before 0.7.2, when storing forwarded credentials, allows attackers to overwrite arbitrary files and change file ownership via unknown vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:kth:heimdal:0.6.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:kth:heimdal:0.6.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:kth:heimdal:0.6.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:kth:heimdal:0.6.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:kth:heimdal:0.6.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:kth:heimdal:0.7.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:kth:heimdal:0.7.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:kth:heimdal:0.7.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:kth:heimdal:0.7.1.3:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:N/I:P/A:N",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 2.1
        },
        "severity" : "LOW",
        "exploitabilityScore" : 3.9,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-08T01:02Z",
    "lastModifiedDate" : "2018-10-19T15:45Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0583",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "clever_copy",
            "product" : {
              "product_data" : [ {
                "product_name" : "clever_copy",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0a",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://retrogod.altervista.org/Clever_Copy_V3_sql_xpl.html",
          "name" : "http://retrogod.altervista.org/Clever_Copy_V3_sql_xpl.html",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://secunia.com/advisories/18749",
          "name" : "18749",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1015590",
          "name" : "1015590",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/22984",
          "name" : "22984",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0462",
          "name" : "ADV-2006-0462",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24545",
          "name" : "clevercopy-mailarticle-sql-injection(24545)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in mailarticle.php in Clever Copy 3.0 and earlier allows remote attackers to execute arbitrary SQL commands via the ID parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clever_copy:clever_copy:1.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clever_copy:clever_copy:1.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clever_copy:clever_copy:1.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clever_copy:clever_copy:1.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clever_copy:clever_copy:2.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clever_copy:clever_copy:2.0a:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clever_copy:clever_copy:3.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-08T01:02Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0584",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "peoplesoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "peopletools",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.40",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.41",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.42",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.43",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.45.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.46.3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.osvdb.org/22952",
          "name" : "22952",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/424086/100/0/threaded",
          "name" : "20060204 PeopleSoft (Oracle) PSCipher Encryption Weakness",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16507",
          "name" : "16507",
          "refsource" : "BID",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The PSCipher function in PeopleSoft People Tools 8.4x uses PKCS #5 with a fixed DES key to store user passwords, which makes it easier for local users to guess passwords using a dictionary attack that compares output strings."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:peoplesoft:peopletools:8.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:peoplesoft:peopletools:8.40:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:peoplesoft:peopletools:8.41:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:peoplesoft:peopletools:8.42:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:peoplesoft:peopletools:8.43:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:peoplesoft:peopletools:8.45.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:peoplesoft:peopletools:8.46.3:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 2.1
        },
        "severity" : "LOW",
        "exploitabilityScore" : 3.9,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-08T01:02Z",
    "lastModifiedDate" : "2018-10-19T15:45Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0585",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "ie",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.01",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.40.308",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.40.520",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.70.1155",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.70.1158",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.70.1215",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.70.1300",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.71.544",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.71.1008.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.71.1712.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.72.2106.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.72.3110.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.72.3612.1713",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.00.0518.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.00.0910.1309",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.00.2014.0216",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.00.2314.1003",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.00.2516.1900",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.00.2614.3500",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.00.2919.800",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.00.2919.3800",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.00.2919.6307",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.00.2920.0000",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.00.3103.1000",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.00.3105.0106",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.00.3314.2101",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.00.3315.1000",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.00.3502.1000",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.00.3700.1000",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.01",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.2.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.50.3825.1300",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.50.4030.2400",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.50.4134.0100",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.50.4134.0600",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.50.4308.2900",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.50.4522.1800",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.50.4807.2300",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://securitytracker.com/id?1015559",
          "name" : "1015559",
          "refsource" : "SECTRACK",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/423675/100/0/threaded",
          "name" : "20060131 Internet Explorer remotely exploitable vulnerability in JScript's document.write() method",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/425422/30/6890/threaded",
          "name" : "20060217 Re: Internet Explorer remotely exploitable vulnerability in JScript's document.write() method",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16441",
          "name" : "16441",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "jscript.dll in Microsoft Internet Explorer 6.0 SP1 and earlier allows remote attackers to cause a denial of service (application crash) via a Shockwave Flash object that contains ActionScript code that calls VBScript, which in turn calls the Javascript document.write function, which triggers a null dereference."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:ie:3.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:ie:3.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:ie:3.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:ie:3.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:ie:3.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:ie:4.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:ie:4.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:ie:4.0.1:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:ie:4.0.1:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:ie:4.01:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:ie:4.01:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:ie:4.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:ie:4.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:ie:4.40.308:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:ie:4.40.520:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:ie:4.70.1155:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:ie:4.70.1158:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:ie:4.70.1215:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:ie:4.70.1300:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:ie:4.71.544:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:ie:4.71.1008.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:ie:4.71.1712.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:ie:4.72.2106.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:ie:4.72.3110.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:ie:4.72.3612.1713:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:ie:5.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:ie:5.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:ie:5.0.1:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:ie:5.0.1:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:ie:5.0.1:sp3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:ie:5.0.1:sp4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:ie:5.00.0518.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:ie:5.00.0910.1309:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:ie:5.00.2014.0216:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:ie:5.00.2314.1003:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:ie:5.00.2516.1900:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:ie:5.00.2614.3500:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:ie:5.00.2919.800:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:ie:5.00.2919.3800:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:ie:5.00.2919.6307:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:ie:5.00.2920.0000:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:ie:5.00.3103.1000:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:ie:5.00.3105.0106:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:ie:5.00.3314.2101:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:ie:5.00.3315.1000:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:ie:5.00.3502.1000:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:ie:5.00.3700.1000:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:ie:5.01:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:ie:5.01:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:ie:5.01:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:ie:5.01:sp3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:ie:5.01:sp4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:ie:5.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:ie:5.2.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:ie:5.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:ie:5.5:preview:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:ie:5.5:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:ie:5.5:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:ie:5.50.3825.1300:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:ie:5.50.4030.2400:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:ie:5.50.4134.0100:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:ie:5.50.4134.0600:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:ie:5.50.4308.2900:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:ie:5.50.4522.1800:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:ie:5.50.4807.2300:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:ie:*:sp1:*:*:*:*:*:*",
          "versionEndIncluding" : "6"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-08T01:02Z",
    "lastModifiedDate" : "2018-10-19T15:45Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0586",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "application_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.1.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.0.3.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.2.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.2.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.2.1.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "oracle10g",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "enterprise_10.1.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "enterprise_10.1.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "enterprise_10.1.0.3.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "enterprise_10.1.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "personal_10.1.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "personal_10.1.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "personal_10.1.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "personal_10.10.3.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "standard_10.1.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "standard_10.1.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "standard_10.1.0.3.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "standard_10.1.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "standard_10.1.0.4.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "standard_10.1.0.5",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.grok.org.uk/pipermail/full-disclosure/2006-January/041498.html",
          "name" : "20060118 Oracle Database 10g Rel. 1 - SQL Injection in SYS.KUPV$FT_INT",
          "refsource" : "FULLDISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://lists.grok.org.uk/pipermail/full-disclosure/2006-January/041499.html",
          "name" : "20060118 Oracle Database 10g Rel. 1 - SQL Injection in SYS.KUPV$FT",
          "refsource" : "FULLDISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/22839",
          "name" : "22839",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/22840",
          "name" : "22840",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.red-database-security.com/advisory/oracle_cpu_jan_2006.html",
          "name" : "http://www.red-database-security.com/advisory/oracle_cpu_jan_2006.html",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.red-database-security.com/advisory/oracle_sql_injection_kupv$ft.html",
          "name" : "http://www.red-database-security.com/advisory/oracle_sql_injection_kupv$ft.html",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.red-database-security.com/advisory/oracle_sql_injection_kupv$ft_int.html",
          "name" : "http://www.red-database-security.com/advisory/oracle_sql_injection_kupv$ft_int.html",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/422423/30/7370/threaded",
          "name" : "20060117 Oracle Database 10g Rel. 1 - SQL Injection in SYS.KUPV$FT",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/422424/30/7370/threaded",
          "name" : "20060117 Oracle Database 10g Rel. 1 - SQL Injection in SYS.KUPV$FT_INT",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16294",
          "name" : "16294",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24195",
          "name" : "oracle-syskupv$ft-sql-injection(24195)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24197",
          "name" : "oracle-syskupv$ftint-sql-injection(24197)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple SQL injection vulnerabilities in Oracle 10g Release 1 before CPU Jan 2006 allow remote attackers to execute arbitrary SQL commands via multiple parameters in (1) ATTACH_JOB, (2) HAS_PRIVS, and (3) OPEN_JOB functions in the SYS.KUPV$FT package; and (4) UPDATE_JOB, (5) ACTIVE_JOB, (6) ATTACH_POSSIBLE, (7) ATTACH_TO_JOB, (8) CREATE_NEW_JOB, (9) DELETE_JOB, (10) DELETE_MASTER_TABLE, (11) DETACH_JOB, (12) GET_JOB_INFO, (13) GET_JOB_QUEUES, (14) GET_SOLE_JOBNAME, (15) MASTER_TBL_LOCK, and (16) VALID_HANDLE functions in the SYS.KUPV$FT_INT package.  NOTE: due to the lack of relevant details from the Oracle advisory, a separate CVE is being created since it cannot be conclusively proven that these issues has been addressed by Oracle.  It is unclear which, if any, Oracle Vuln# identifiers apply to these issues."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_server:10.1.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_server:10.1.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_server:10.1.0.3.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_server:10.1.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_server:10.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_server:10.1.2.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_server:10.1.2.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_server:10.1.2.1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:oracle10g:enterprise_10.1.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:oracle10g:enterprise_10.1.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:oracle10g:enterprise_10.1.0.3.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:oracle10g:enterprise_10.1.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:oracle10g:personal_10.1.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:oracle10g:personal_10.1.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:oracle10g:personal_10.1.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:oracle10g:personal_10.10.3.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:oracle10g:standard_10.1.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:oracle10g:standard_10.1.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:oracle10g:standard_10.1.0.3.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:oracle10g:standard_10.1.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:oracle10g:standard_10.1.0.4.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:oracle10g:standard_10.1.0.5:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-08T01:02Z",
    "lastModifiedDate" : "2018-10-19T15:45Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0587",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "gallery_project",
            "product" : {
              "product_data" : [ {
                "product_name" : "gallery",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.3.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.3_pl1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.3_pl2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.4_pl2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.4_pl3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.4_pl4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.4_pl5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4_pl1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4_pl2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.1_rc2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.2_rc2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://archives.neohapsis.com/archives/bugtraq/2006-02/0224.html",
          "name" : "20060214 Digital Armaments Security Advisory 02.14.2006: Gallery web-based photo gallery remote file execution",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://archives.neohapsis.com/archives/bugtraq/2006-02/0286.html",
          "name" : "20060216 Re: Digital Armaments Security Advisory 02.14.2006: Gallery web-based photo gallery remote file execution",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://gallery.menalto.com/gallery_1_5_2_pl2_security_release",
          "name" : "http://gallery.menalto.com/gallery_1_5_2_pl2_security_release",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://secunia.com/advisories/18735",
          "name" : "18735",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1015641",
          "name" : "1015641",
          "refsource" : "SECTRACK",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.digitalarmaments.com/2006140293402395.html",
          "name" : "http://www.digitalarmaments.com/2006140293402395.html",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/22944",
          "name" : "22944",
          "refsource" : "OSVDB",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.osvdb.org/23256",
          "name" : "23256",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16533",
          "name" : "16533",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24538",
          "name" : "gallery-album-data-modification(24538)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24768",
          "name" : "gallery-util-file-include(24768)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in util.php in Gallery before 1.5.2-pl2 allows remote authenticated users with trick an owner into modifying stored album data and possibly executing arbitrary code via unspecified vectors involving a crafted link to a crafted file."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:gallery_project:gallery:1.3.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:gallery_project:gallery:1.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:gallery_project:gallery:1.4.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:gallery_project:gallery:1.4.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:gallery_project:gallery:1.4.3_pl1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:gallery_project:gallery:1.4.3_pl2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:gallery_project:gallery:1.4.4_pl2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:gallery_project:gallery:1.4.4_pl3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:gallery_project:gallery:1.4.4_pl4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:gallery_project:gallery:1.4.4_pl5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:gallery_project:gallery:1.4_pl1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:gallery_project:gallery:1.4_pl2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:gallery_project:gallery:1.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:gallery_project:gallery:1.5.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:gallery_project:gallery:1.5.1_rc2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:gallery_project:gallery:1.5.2_rc2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.5
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-08T01:02Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0588",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "jaia_interactive",
            "product" : {
              "product_data" : [ {
                "product_name" : "mytopix",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.2.3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://kapda.ir/advisory-249.html",
          "name" : "http://kapda.ir/advisory-249.html",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/413",
          "name" : "413",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/423950/100/0/threaded",
          "name" : "20060204 [KAPDA::#26] - MyTopix Sql Injection & Path Disclosure",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24502",
          "name" : "mytopix-search-sql-injection(24502)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in search.php in MyTopix 1.2.3 allows remote attackers to execute arbitrary SQL commands via the (1) mid and (2) keywords parameters."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:jaia_interactive:mytopix:1.2.3:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-08T01:02Z",
    "lastModifiedDate" : "2018-10-19T15:45Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0589",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "jaia_interactive",
            "product" : {
              "product_data" : [ {
                "product_name" : "mytopix",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.2.3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://kapda.ir/advisory-249.html",
          "name" : "http://kapda.ir/advisory-249.html",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/413",
          "name" : "413",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/423950/100/0/threaded",
          "name" : "20060204 [KAPDA::#26] - MyTopix Sql Injection & Path Disclosure",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "MyTopix 1.2.3 allows remote attackers to obtain the installation path via a direct request to logon.mod.php, which leaks the path in an error message."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:jaia_interactive:mytopix:1.2.3:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-08T01:02Z",
    "lastModifiedDate" : "2018-10-19T15:45Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0590",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "jaia_interactive",
            "product" : {
              "product_data" : [ {
                "product_name" : "mytopix",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.2.3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://kapda.ir/advisory-249.html",
          "name" : "http://kapda.ir/advisory-249.html",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/413",
          "name" : "413",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/423950/100/0/threaded",
          "name" : "20060204 [KAPDA::#26] - MyTopix Sql Injection & Path Disclosure",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "MyTopix 1.2.3 allows remote attackers to obtain the installation path via an invalid hl parameter to index.php, which leads to path disclosure, possibly related to invalid SQL syntax."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:jaia_interactive:mytopix:1.2.3:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-08T01:02Z",
    "lastModifiedDate" : "2018-10-19T15:45Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0591",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "solar_designer",
            "product" : {
              "product_data" : [ {
                "product_name" : "crypt_blowfish",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.4.7",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-310"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "ftp://patches.sgi.com/support/free/security/advisories/20060602-01-U.asc",
          "name" : "20060602-01-U",
          "refsource" : "SGI",
          "tags" : [ ]
        }, {
          "url" : "http://cvsweb.openwall.com/cgi/cvsweb.cgi/Owl/packages/glibc/crypt_blowfish/crypt_gensalt.c?only_with_tag=CRYPT_BLOWFISH_1_0",
          "name" : "http://cvsweb.openwall.com/cgi/cvsweb.cgi/Owl/packages/glibc/crypt_blowfish/crypt_gensalt.c?only_with_tag=CRYPT_BLOWFISH_1_0",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18772",
          "name" : "18772",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/20232",
          "name" : "20232",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/20653",
          "name" : "20653",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/20782",
          "name" : "20782",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://support.avaya.com/elmodocs2/security/ASA-2006-113.htm",
          "name" : "http://support.avaya.com/elmodocs2/security/ASA-2006-113.htm",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/23005",
          "name" : "23005",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2006-0526.html",
          "name" : "RHSA-2006:0526",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/424260/100/0/threaded",
          "name" : "20060207 crypt_blowfish 1.0",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0477",
          "name" : "ADV-2006-0477",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24590",
          "name" : "cryptblowfish-salt-information-disclosure(24590)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11502",
          "name" : "oval:org.mitre.oval:def:11502",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The crypt_gensalt functions for BSDI-style extended DES-based and FreeBSD-sytle MD5-based password hashes in crypt_blowfish 0.4.7 and earlier do not evenly and randomly distribute salts, which makes it easier for attackers to guess passwords from a stolen password file due to the increased number of collisions."
        }, {
          "lang" : "en",
          "value" : "This vulnerability may only be exploited in conjunction with another vulnerability.  The password file (normally shadowed) must first be stolen."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:solar_designer:crypt_blowfish:0.4.7:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:H/Au:N/C:P/I:N/A:N",
          "accessVector" : "LOCAL",
          "accessComplexity" : "HIGH",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 1.2
        },
        "severity" : "LOW",
        "exploitabilityScore" : 1.9,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-08T01:02Z",
    "lastModifiedDate" : "2018-10-19T15:45Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0592",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "lexmark",
            "product" : {
              "product_data" : [ {
                "product_name" : "printer_sharing",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.29",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.41",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18744",
          "name" : "18744",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1015593",
          "name" : "1015593",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/424273/100/0/threaded",
          "name" : "20060207 High Risk Vulnerability in Lexmark Printer Sharing Service",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0481",
          "name" : "ADV-2006-0481",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24581",
          "name" : "lexmark-lexpps-code-execution(24581)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Lexmark Printer Sharing LexBce Server Service (LexPPS), possibly 8.29 and 9.41, allows remote attackers to execute arbitrary code via unspecified vectors.  NOTE: This information is based on a vague initial disclosure; details will be updated after the grace period has ended."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:lexmark:printer_sharing:8.29:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:lexmark:printer_sharing:9.41:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-08T01:02Z",
    "lastModifiedDate" : "2018-10-19T15:45Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0593",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "php_fusion",
            "product" : {
              "product_data" : [ {
                "product_name" : "php_fusion",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.00.100",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.00.101",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.00.102",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.00.103",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.00.104",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.00.105",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.00.106",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.00.107",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.00.108",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.00.109",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.00.110",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.00.200",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.00.204",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.00.205",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.00.206",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.00.207",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.00.300",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.00.303",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18949",
          "name" : "18949",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/22980",
          "name" : "22980",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/22981",
          "name" : "22981",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.php-fusion.co.uk/downloads.php?cat_id=3",
          "name" : "http://www.php-fusion.co.uk/downloads.php?cat_id=3",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.php-fusion.co.uk/news.php?readmore=307",
          "name" : "http://www.php-fusion.co.uk/news.php?readmore=307",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16548",
          "name" : "16548",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0463",
          "name" : "ADV-2006-0463",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24548",
          "name" : "phpfusion-multiple-xss(24548)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in PHP-Fusion before 6.00.304 allows remote attackers to inject arbitrary web script or HTML via the (1) shout_name field in shoutbox_panel.php and the (2) comments field in comments_include.php."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php_fusion:php_fusion:6.00.100:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php_fusion:php_fusion:6.00.101:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php_fusion:php_fusion:6.00.102:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php_fusion:php_fusion:6.00.103:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php_fusion:php_fusion:6.00.104:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php_fusion:php_fusion:6.00.105:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php_fusion:php_fusion:6.00.106:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php_fusion:php_fusion:6.00.107:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php_fusion:php_fusion:6.00.108:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php_fusion:php_fusion:6.00.109:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php_fusion:php_fusion:6.00.110:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php_fusion:php_fusion:6.00.200:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php_fusion:php_fusion:6.00.204:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php_fusion:php_fusion:6.00.205:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php_fusion:php_fusion:6.00.206:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php_fusion:php_fusion:6.00.207:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php_fusion:php_fusion:6.00.300:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php_fusion:php_fusion:6.00.303:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-08T01:02Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0597",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "stefan_ritt",
            "product" : {
              "product_data" : [ {
                "product_name" : "elog_web_logbook",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.5.6",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://bugs.debian.org/cgi-bin/bugreport.cgi/0001-r1333-Fixed-crashes-with-very-long-revisions-attributes.txt?bug=349528;msg=15;att=1",
          "name" : "http://bugs.debian.org/cgi-bin/bugreport.cgi/0001-r1333-Fixed-crashes-with-very-long-revisions-attributes.txt?bug=349528;msg=15;att=1",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=349528",
          "name" : "http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=349528",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18783",
          "name" : "18783",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.debian.org/security/2006/dsa-967",
          "name" : "DSA-967",
          "refsource" : "DEBIAN",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16579",
          "name" : "16579",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24704",
          "name" : "elog-elogd-bo(24704)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple stack-based buffer overflows in elogd.c in elog before 2.5.7 r1558-4 allow attackers to cause a denial of service (application crash) and possibly execute code via long \"revision attributes\"."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:stefan_ritt:elog_web_logbook:2.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:stefan_ritt:elog_web_logbook:2.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:stefan_ritt:elog_web_logbook:2.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:stefan_ritt:elog_web_logbook:2.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:stefan_ritt:elog_web_logbook:2.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:stefan_ritt:elog_web_logbook:2.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:stefan_ritt:elog_web_logbook:2.1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:stefan_ritt:elog_web_logbook:2.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:stefan_ritt:elog_web_logbook:2.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:stefan_ritt:elog_web_logbook:2.1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:stefan_ritt:elog_web_logbook:2.2.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:stefan_ritt:elog_web_logbook:2.2.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:stefan_ritt:elog_web_logbook:2.2.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:stefan_ritt:elog_web_logbook:2.2.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:stefan_ritt:elog_web_logbook:2.2.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:stefan_ritt:elog_web_logbook:2.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:stefan_ritt:elog_web_logbook:2.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:stefan_ritt:elog_web_logbook:2.5.6:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-13T11:06Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0598",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "stefan_ritt",
            "product" : {
              "product_data" : [ {
                "product_name" : "elog_web_logbook",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.5.6",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://bugs.debian.org/cgi-bin/bugreport.cgi/0002-r1335-Applied-patch-from-Emiliano-to-fix-possible-buffer-overflow.txt?bug=349528;msg=15;att=2",
          "name" : "http://bugs.debian.org/cgi-bin/bugreport.cgi/0002-r1335-Applied-patch-from-Emiliano-to-fix-possible-buffer-overflow.txt?bug=349528;msg=15;att=2",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=349528",
          "name" : "http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=349528",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18783",
          "name" : "18783",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.debian.org/security/2006/dsa-967",
          "name" : "DSA-967",
          "refsource" : "DEBIAN",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16579",
          "name" : "16579",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24705",
          "name" : "elog-elogd-log-bo(24705)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Buffer overflow in elogd.c in elog before 2.5.7 r1558-4 allows attackers to execute code via unspecified variables, when writing to the log file."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:stefan_ritt:elog_web_logbook:2.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:stefan_ritt:elog_web_logbook:2.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:stefan_ritt:elog_web_logbook:2.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:stefan_ritt:elog_web_logbook:2.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:stefan_ritt:elog_web_logbook:2.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:stefan_ritt:elog_web_logbook:2.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:stefan_ritt:elog_web_logbook:2.1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:stefan_ritt:elog_web_logbook:2.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:stefan_ritt:elog_web_logbook:2.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:stefan_ritt:elog_web_logbook:2.1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:stefan_ritt:elog_web_logbook:2.2.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:stefan_ritt:elog_web_logbook:2.2.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:stefan_ritt:elog_web_logbook:2.2.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:stefan_ritt:elog_web_logbook:2.2.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:stefan_ritt:elog_web_logbook:2.2.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:stefan_ritt:elog_web_logbook:2.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:stefan_ritt:elog_web_logbook:2.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:stefan_ritt:elog_web_logbook:2.5.6:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-13T11:06Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0599",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "stefan_ritt",
            "product" : {
              "product_data" : [ {
                "product_name" : "elog_web_logbook",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.5.6",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://bugs.debian.org/cgi-bin/bugreport.cgi/0003-r1472-Do-not-distinguish-between-invalid-user-name-and-invalid-password.txt?bug=349528;msg=15;att=3",
          "name" : "http://bugs.debian.org/cgi-bin/bugreport.cgi/0003-r1472-Do-not-distinguish-between-invalid-user-name-and-invalid-password.txt?bug=349528;msg=15;att=3",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=349528",
          "name" : "http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=349528",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18783",
          "name" : "18783",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.debian.org/security/2006/dsa-967",
          "name" : "DSA-967",
          "refsource" : "DEBIAN",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16579",
          "name" : "16579",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24706",
          "name" : "elog-elog-elogd-user-enumeration(24706)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The (1) elog.c and (2) elogd.c components in elog before 2.5.7 r1558-4 generate different responses depending on whether or not a username is valid, which allows remote attackers to determine valid usernames."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:stefan_ritt:elog_web_logbook:2.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:stefan_ritt:elog_web_logbook:2.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:stefan_ritt:elog_web_logbook:2.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:stefan_ritt:elog_web_logbook:2.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:stefan_ritt:elog_web_logbook:2.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:stefan_ritt:elog_web_logbook:2.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:stefan_ritt:elog_web_logbook:2.1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:stefan_ritt:elog_web_logbook:2.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:stefan_ritt:elog_web_logbook:2.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:stefan_ritt:elog_web_logbook:2.1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:stefan_ritt:elog_web_logbook:2.2.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:stefan_ritt:elog_web_logbook:2.2.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:stefan_ritt:elog_web_logbook:2.2.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:stefan_ritt:elog_web_logbook:2.2.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:stefan_ritt:elog_web_logbook:2.2.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:stefan_ritt:elog_web_logbook:2.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:stefan_ritt:elog_web_logbook:2.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:stefan_ritt:elog_web_logbook:2.5.6:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-13T11:06Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0600",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "stefan_ritt",
            "product" : {
              "product_data" : [ {
                "product_name" : "elog_web_logbook",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.5.6",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=349528",
          "name" : "http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=349528",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://savannah.psi.ch/viewcvs/trunk/src/elogd.c?root=elog&rev=1487&view=diff&r1=1487&r2=1486&p1=trunk/src/elogd.c&p2=/trunk/src/elogd.c",
          "name" : "http://savannah.psi.ch/viewcvs/trunk/src/elogd.c?root=elog&rev=1487&view=diff&r1=1487&r2=1486&p1=trunk/src/elogd.c&p2=/trunk/src/elogd.c",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18783",
          "name" : "18783",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.debian.org/security/2006/dsa-967",
          "name" : "DSA-967",
          "refsource" : "DEBIAN",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16579",
          "name" : "16579",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24707",
          "name" : "elog-fail-redirect-dos(24707)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "elog before 2.5.7 r1558-4 allows remote attackers to cause a denial of service (infinite redirection) via a request with the fail parameter set to 1, which redirects to the same request."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:stefan_ritt:elog_web_logbook:2.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:stefan_ritt:elog_web_logbook:2.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:stefan_ritt:elog_web_logbook:2.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:stefan_ritt:elog_web_logbook:2.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:stefan_ritt:elog_web_logbook:2.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:stefan_ritt:elog_web_logbook:2.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:stefan_ritt:elog_web_logbook:2.1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:stefan_ritt:elog_web_logbook:2.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:stefan_ritt:elog_web_logbook:2.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:stefan_ritt:elog_web_logbook:2.1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:stefan_ritt:elog_web_logbook:2.2.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:stefan_ritt:elog_web_logbook:2.2.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:stefan_ritt:elog_web_logbook:2.2.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:stefan_ritt:elog_web_logbook:2.2.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:stefan_ritt:elog_web_logbook:2.2.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:stefan_ritt:elog_web_logbook:2.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:stefan_ritt:elog_web_logbook:2.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:stefan_ritt:elog_web_logbook:2.5.6:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-13T11:06Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0602",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "hinton_design",
            "product" : {
              "product_data" : [ {
                "product_name" : "phphg_guestbook",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://evuln.com/vulns/58/summary.html",
          "name" : "http://evuln.com/vulns/58/summary.html",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://secunia.com/advisories/18758",
          "name" : "18758",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1015620",
          "name" : "1015620",
          "refsource" : "SECTRACK",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/424740/100/0/threaded",
          "name" : "20060211 [eVuln] phphg Guestbook Multiple Vulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16541",
          "name" : "16541",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0480",
          "name" : "ADV-2006-0480",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple SQL injection vulnerabilities in Hinton Design phphg Guestbook 1.2 allow remote attackers to execute arbitrary SQL commands via the (1) username parameter to check.php or the id parameter to (2) admin/edit_smilie.php, (3) admin/add_theme.php, (4) admin/ban_ip.php, (5) admin/add_lang.php, or (6) admin/edit_filter.php."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hinton_design:phphg_guestbook:1.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-08T23:02Z",
    "lastModifiedDate" : "2018-10-19T15:45Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0603",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "hinton_design",
            "product" : {
              "product_data" : [ {
                "product_name" : "phphg_guestbook",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://evuln.com/vulns/58/summary.html",
          "name" : "http://evuln.com/vulns/58/summary.html",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18758",
          "name" : "18758",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1015620",
          "name" : "1015620",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/424740/100/0/threaded",
          "name" : "20060211 [eVuln] phphg Guestbook Multiple Vulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16541",
          "name" : "16541",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0480",
          "name" : "ADV-2006-0480",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple cross-site scripting vulnerabilities in signed.php in Hinton Design phphg Guestbook 1.2 allow remote attackers to inject arbitrary web script or HTML via the (1) location, (2) website, or (3) message parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hinton_design:phphg_guestbook:1.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 6.4
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-08T23:02Z",
    "lastModifiedDate" : "2018-10-19T15:45Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0604",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "hinton_design",
            "product" : {
              "product_data" : [ {
                "product_name" : "phphg_guestbook",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://evuln.com/vulns/58/description.html",
          "name" : "http://evuln.com/vulns/58/description.html",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18758",
          "name" : "18758",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1015620",
          "name" : "1015620",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/424740/100/0/threaded",
          "name" : "20060211 [eVuln] phphg Guestbook Multiple Vulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16541",
          "name" : "16541",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0480",
          "name" : "ADV-2006-0480",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "check.php in Hinton Design phphg Guestbook 1.2 does not check the user password when authenticating via cookies, which allows remote attackers to gain unauthorized access."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hinton_design:phphg_guestbook:1.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-08T23:02Z",
    "lastModifiedDate" : "2018-10-19T15:45Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0605",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "unknown_domain",
            "product" : {
              "product_data" : [ {
                "product_name" : "shoutbox",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2005-07-21",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://evuln.com/vulns/55/summary.html",
          "name" : "http://evuln.com/vulns/55/summary.html",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18759",
          "name" : "18759",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/424679/100/0/threaded",
          "name" : "20060209 [eVuln] Unknown Domain Shoutbox multiple XSS & SQL Injection Vulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16543",
          "name" : "16543",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0476",
          "name" : "ADV-2006-0476",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24440",
          "name" : "shoutbox-multiple-xss(24440)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple cross-site scripting (XSS) vulnerabilities in Unknown Domain Shoutbox 2005.07.21 allow remote attackers to inject arbitrary web script or HTML, possibly via the (1) Handle or (2) Message fields."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:unknown_domain:shoutbox:2005-07-21:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-08T23:02Z",
    "lastModifiedDate" : "2018-10-19T15:45Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0606",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "unknown_domain",
            "product" : {
              "product_data" : [ {
                "product_name" : "shoutbox",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2005-07-21",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://evuln.com/vulns/55/summary.html",
          "name" : "http://evuln.com/vulns/55/summary.html",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18759",
          "name" : "18759",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/424679/100/0/threaded",
          "name" : "20060209 [eVuln] Unknown Domain Shoutbox multiple XSS & SQL Injection Vulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16543",
          "name" : "16543",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0476",
          "name" : "ADV-2006-0476",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in Unknown Domain Shoutbox 2005.07.21 allows remote attackers to execute arbitrary SQL commands via unknown attack vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:unknown_domain:shoutbox:2005-07-21:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-08T23:02Z",
    "lastModifiedDate" : "2018-10-19T15:45Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0607",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "hinton_design",
            "product" : {
              "product_data" : [ {
                "product_name" : "phphd",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18793",
          "name" : "18793",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.evuln.com/vulns/60/summary.html",
          "name" : "http://www.evuln.com/vulns/60/summary.html",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/23026",
          "name" : "23026",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/424827/100/0/threaded",
          "name" : "20060212 [eVuln] phphd Multiple Vulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16586",
          "name" : "16586",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24510",
          "name" : "phphd-check-security-bypass(24510)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "check.php in Hinton Design phphd 1.0 does not check passwords when certain cookies are provided, which allows remote attackers to bypass authentication."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hinton_design:phphd:1.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-08T23:02Z",
    "lastModifiedDate" : "2018-10-19T15:45Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0608",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "hinton_design",
            "product" : {
              "product_data" : [ {
                "product_name" : "phphd",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18793",
          "name" : "18793",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.evuln.com/vulns/60/summary.html",
          "name" : "http://www.evuln.com/vulns/60/summary.html",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/23025",
          "name" : "23025",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/23028",
          "name" : "23028",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/424827/100/0/threaded",
          "name" : "20060212 [eVuln] phphd Multiple Vulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16586",
          "name" : "16586",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24508",
          "name" : "phphd-check-sql-injection(24508)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24515",
          "name" : "phphd-multiple-sql-injection(24515)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple SQL injection vulnerabilities in Hinton Design phphd 1.0 allow remote attackers to execute arbitrary SQL commands via (1) the username parameter to check.php or (2) unknown attack vectors to scripts that display information from the database."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hinton_design:phphd:1.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-08T23:02Z",
    "lastModifiedDate" : "2018-10-19T15:45Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0609",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "hinton_design",
            "product" : {
              "product_data" : [ {
                "product_name" : "phphd",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18793",
          "name" : "18793",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.evuln.com/vulns/60/summary.html",
          "name" : "http://www.evuln.com/vulns/60/summary.html",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/23027",
          "name" : "23027",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/424827/100/0/threaded",
          "name" : "20060212 [eVuln] phphd Multiple Vulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16586",
          "name" : "16586",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24513",
          "name" : "phphd-add-xss(24513)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in add.php in Hinton Design phphd 1.0 allows remote attackers to inject arbitrary web script or HTML via unknown vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hinton_design:phphd:1.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-08T23:02Z",
    "lastModifiedDate" : "2018-10-19T15:45Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0610",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "2200net",
            "product" : {
              "product_data" : [ {
                "product_name" : "2200net_calendar",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://marc.info/?l=bugtraq&m=114003781801861&w=2",
          "name" : "20060215 [eVuln] 2200net Calendar system SQL Injection and Authentication",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18781",
          "name" : "18781",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.evuln.com/vulns/62/summary.html",
          "name" : "http://www.evuln.com/vulns/62/summary.html",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/23037",
          "name" : "23037",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/23038",
          "name" : "23038",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/425094/100/0/threaded",
          "name" : "20060215 [eVuln] 2200net Calendar system SQL Injection and Authentication Bypass Vulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16569",
          "name" : "16569",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0486",
          "name" : "ADV-2006-0486",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24483",
          "name" : "2200net-calendar-sql-injection(24483)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24484",
          "name" : "2200net-adminlogin-sql-injection(24484)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple SQL injection vulnerabilities in 2200net Calendar system 1.2, with gpc_magic_quotes disabled, allow remote attackers to execute arbitrary SQL commands and bypass authentication via (1) the fm_data[id] parameter to calendar.php and (2) the $ad['acc'] variable in adminlogin.php."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:2200net:2200net_calendar:1.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-09T00:02Z",
    "lastModifiedDate" : "2018-10-19T15:45Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0611",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "atmail",
            "product" : {
              "product_data" : [ {
                "product_name" : "atmail",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://kb.atmail.com/view_article.php?num=374",
          "name" : "http://kb.atmail.com/view_article.php?num=374",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://secunia.com/advisories/18646",
          "name" : "18646",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/22882",
          "name" : "22882",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16470",
          "name" : "16470",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0415",
          "name" : "ADV-2006-0415",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24459",
          "name" : "@mail-compose-directory-traversal(24459)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Directory traversal vulnerability in compose.pl in @Mail 4.3 and earlier for Windows allows remote attackers to upload arbitrary files to arbitrary locations via a .. (dot dot) in the unique parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:atmail:atmail:4.3:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-09T00:02Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0612",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "powersave",
            "product" : {
              "product_data" : [ {
                "product_name" : "powersave",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.10.10",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18651",
          "name" : "18651",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://sourceforge.net/project/shownotes.php?release_id=379792&group_id=124576",
          "name" : "http://sourceforge.net/project/shownotes.php?release_id=379792&group_id=124576",
          "refsource" : "MISC",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16469",
          "name" : "16469",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0416",
          "name" : "ADV-2006-0416",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24458",
          "name" : "powersave-daemon-gain-privileges(24458)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Powersave daemon before 0.10.15.2 allows local users to gain privileges (unauthorized access to an X session) via unspecified vectors. NOTE: the provenance of this information is unknown; portions of the details are obtained from third party information."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:powersave:powersave:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "0.10.10"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 4.6
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 3.9,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-09T00:02Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0613",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "sun",
            "product" : {
              "product_data" : [ {
                "product_name" : "j2se",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.0_update5",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://docs.info.apple.com/article.html?artnum=303658",
          "name" : "http://docs.info.apple.com/article.html?artnum=303658",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18762",
          "name" : "18762",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1015597",
          "name" : "1015597",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://sunsolve.sun.com/search/document.do?assetkey=1-26-102170-1",
          "name" : "102170",
          "refsource" : "SUNALERT",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/652636",
          "name" : "VU#652636",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16540",
          "name" : "16540",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0468",
          "name" : "ADV-2006-0468",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/1398",
          "name" : "ADV-2006-1398",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24568",
          "name" : "javawebstart-jnlp-privilege-elevation(24568)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in Java Web Start after 1.0.1_02, as used in J2SE 5.0 Update 5 and earlier, allows remote attackers to obtain privileges via unspecified vectors involving untrusted applications."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sun:j2se:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "5.0_update5"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:H/Au:N/C:P/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "HIGH",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 4.9,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2006-02-09T02:02Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0614",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "sun",
            "product" : {
              "product_data" : [ {
                "product_name" : "jdk",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "jre",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.3.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.1_2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.1_03",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.1_04",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.1_05",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.1_06",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.1_07",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.1_08",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.1_09",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.1_10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.1_11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.1_12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.1_13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.1_14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.1_15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.1_16",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.2_1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.2_2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.2_3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.2_4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.2_5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.2_6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.2_7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.2_8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "sdk",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.3.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.0_01",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.0_02",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.0_03",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.0_04",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.0_05",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.1_01",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.1_01a",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.1_02",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.1_03",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.1_04",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.1_05",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.1_06",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.1_07",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.1_08",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.1_09",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.1_10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.1_11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.1_12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.1_13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.1_14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.1_15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.1_16",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.2_1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.2_02",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.2_2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.2_03",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.2_3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.2_04",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.2_4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.2_5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.2_6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.2_7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.2_08",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.2_8",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://docs.info.apple.com/article.html?artnum=303658",
          "name" : "http://docs.info.apple.com/article.html?artnum=303658",
          "refsource" : "CONFIRM",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18760",
          "name" : "18760",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18884",
          "name" : "18884",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1015596",
          "name" : "1015596",
          "refsource" : "SECTRACK",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://sunsolve.sun.com/search/document.do?assetkey=1-26-102171-1",
          "name" : "102171",
          "refsource" : "SUNALERT",
          "tags" : [ "Broken Link", "Patch" ]
        }, {
          "url" : "http://www.gentoo.org/security/en/glsa/glsa-200602-07.xml",
          "name" : "GLSA-200602-07",
          "refsource" : "GENTOO",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/759996",
          "name" : "VU#759996",
          "refsource" : "CERT-VN",
          "tags" : [ "Third Party Advisory", "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0467",
          "name" : "ADV-2006-0467",
          "refsource" : "VUPEN",
          "tags" : [ "Permissions Required", "Third Party Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0828",
          "name" : "ADV-2006-0828",
          "refsource" : "VUPEN",
          "tags" : [ "Permissions Required", "Third Party Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/1398",
          "name" : "ADV-2006-1398",
          "refsource" : "VUPEN",
          "tags" : [ "Permissions Required", "Third Party Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24561",
          "name" : "sun-jre-reflection-privilege-elevation(24561)",
          "refsource" : "XF",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in Sun Java JDK and JRE 5.0 Update 3 and earlier, SDK and JRE 1.3.x through 1.3.1_16 and 1.4.x through 1.4.2_08 allows remote attackers to bypass Java sandbox security and obtain privileges via unspecified vectors involving the reflection APIs, aka the \"first issue.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sun:jdk:5.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sun:jdk:5.0:update1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sun:jdk:5.0:update2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sun:jdk:5.0:update3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sun:jre:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "1.3.0",
          "versionEndIncluding" : "1.3.1_16"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sun:jre:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "1.4.0",
          "versionEndIncluding" : "1.4.2_8"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sun:jre:5.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sun:jre:5.0:update1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sun:jre:5.0:update2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sun:jre:5.0:update3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sun:sdk:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "1.3.0",
          "versionEndIncluding" : "1.3.1_16"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sun:sdk:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "1.4.0",
          "versionEndIncluding" : "1.4.2_08"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 6.4
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-09T02:02Z",
    "lastModifiedDate" : "2018-10-04T22:11Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0615",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "sun",
            "product" : {
              "product_data" : [ {
                "product_name" : "jdk",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.5.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "jre",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.4.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.2_1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.2_2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.2_3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.2_4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.2_5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.2_6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.2_7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.2_8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.2_9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "sdk",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.4.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.2_1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.2_2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.2_3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.2_4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.2_5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.2_6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.2_7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.2_8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.2_9",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://docs.info.apple.com/article.html?artnum=303658",
          "name" : "http://docs.info.apple.com/article.html?artnum=303658",
          "refsource" : "CONFIRM",
          "tags" : [ "Broken Link" ]
        }, {
          "url" : "http://secunia.com/advisories/18760",
          "name" : "18760",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Third Party Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18884",
          "name" : "18884",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1015596",
          "name" : "1015596",
          "refsource" : "SECTRACK",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://sunsolve.sun.com/search/document.do?assetkey=1-26-102171-1",
          "name" : "102171",
          "refsource" : "SUNALERT",
          "tags" : [ "Broken Link", "Patch" ]
        }, {
          "url" : "http://www.gentoo.org/security/en/glsa/glsa-200602-07.xml",
          "name" : "GLSA-200602-07",
          "refsource" : "GENTOO",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/759996",
          "name" : "VU#759996",
          "refsource" : "CERT-VN",
          "tags" : [ "Third Party Advisory", "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0467",
          "name" : "ADV-2006-0467",
          "refsource" : "VUPEN",
          "tags" : [ "Permissions Required" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0828",
          "name" : "ADV-2006-0828",
          "refsource" : "VUPEN",
          "tags" : [ "Permissions Required" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/1398",
          "name" : "ADV-2006-1398",
          "refsource" : "VUPEN",
          "tags" : [ "Permissions Required" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24561",
          "name" : "sun-jre-reflection-privilege-elevation(24561)",
          "refsource" : "XF",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple unspecified vulnerabilities in Sun Java JDK and JRE 5.0 Update 4 and earlier, SDK and JRE 1.4.x through 1.4.2_09 allow remote attackers to bypass Java sandbox security and obtain privileges via unspecified vectors involving the reflection APIs, aka the \"second and third issues.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sun:jdk:1.5.0:-:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sun:jdk:1.5.0:update1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sun:jdk:1.5.0:update2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sun:jdk:1.5.0:update3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sun:jdk:1.5.0:update4:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sun:jre:1.4.2:-:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sun:jre:1.4.2_1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sun:jre:1.4.2_2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sun:jre:1.4.2_3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sun:jre:1.4.2_4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sun:jre:1.4.2_5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sun:jre:1.4.2_6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sun:jre:1.4.2_7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sun:jre:1.4.2_8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sun:jre:1.4.2_9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sun:jre:1.5.0:-:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sun:jre:1.5.0:update1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sun:jre:1.5.0:update2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sun:jre:1.5.0:update4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sun:jre:1.5.0:update5:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sun:sdk:1.4.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sun:sdk:1.4.2_1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sun:sdk:1.4.2_2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sun:sdk:1.4.2_3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sun:sdk:1.4.2_4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sun:sdk:1.4.2_5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sun:sdk:1.4.2_6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sun:sdk:1.4.2_7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sun:sdk:1.4.2_8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sun:sdk:1.4.2_9:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:H/Au:N/C:P/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "HIGH",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 4.9,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2006-02-09T02:02Z",
    "lastModifiedDate" : "2019-07-31T12:44Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0616",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "sun",
            "product" : {
              "product_data" : [ {
                "product_name" : "jdk",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.5.0",
                    "version_affected" : "<="
                  } ]
                }
              }, {
                "product_name" : "jre",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.5.0",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://docs.info.apple.com/article.html?artnum=303658",
          "name" : "http://docs.info.apple.com/article.html?artnum=303658",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18760",
          "name" : "18760",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18884",
          "name" : "18884",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1015596",
          "name" : "1015596",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://sunsolve.sun.com/search/document.do?assetkey=1-26-102171-1",
          "name" : "102171",
          "refsource" : "SUNALERT",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.gentoo.org/security/en/glsa/glsa-200602-07.xml",
          "name" : "GLSA-200602-07",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/759996",
          "name" : "VU#759996",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0467",
          "name" : "ADV-2006-0467",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0828",
          "name" : "ADV-2006-0828",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/1398",
          "name" : "ADV-2006-1398",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24561",
          "name" : "sun-jre-reflection-privilege-elevation(24561)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in Sun Java JDK and JRE 5.0 Update 4 and earlier allows remote attackers to bypass Java sandbox security and obtain privileges via unspecified vectors involving the reflection APIs, aka the \"fourth issue.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sun:jdk:*:update4:*:*:*:*:*:*",
          "versionEndIncluding" : "1.5.0"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sun:jre:*:update4:*:*:*:*:*:*",
          "versionEndIncluding" : "1.5.0"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:H/Au:N/C:P/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "HIGH",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 4.9,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2006-02-09T02:02Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0617",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "sun",
            "product" : {
              "product_data" : [ {
                "product_name" : "jdk",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.5.0",
                    "version_affected" : "<="
                  } ]
                }
              }, {
                "product_name" : "jre",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.5.0",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://docs.info.apple.com/article.html?artnum=303658",
          "name" : "http://docs.info.apple.com/article.html?artnum=303658",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18760",
          "name" : "18760",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18884",
          "name" : "18884",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1015596",
          "name" : "1015596",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://sunsolve.sun.com/search/document.do?assetkey=1-26-102171-1",
          "name" : "102171",
          "refsource" : "SUNALERT",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.gentoo.org/security/en/glsa/glsa-200602-07.xml",
          "name" : "GLSA-200602-07",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/759996",
          "name" : "VU#759996",
          "refsource" : "CERT-VN",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0467",
          "name" : "ADV-2006-0467",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0828",
          "name" : "ADV-2006-0828",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/1398",
          "name" : "ADV-2006-1398",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24561",
          "name" : "sun-jre-reflection-privilege-elevation(24561)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple unspecified vulnerabilities in Sun Java JDK and JRE 5.0 Update 5 and earlier allow remote attackers to bypass Java sandbox security and obtain privileges via unspecified vectors involving the reflection APIs, aka the \"fifth, sixth, and seventh issues.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sun:jdk:*:update5:*:*:*:*:*:*",
          "versionEndIncluding" : "1.5.0"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sun:jre:*:update5:*:*:*:*:*:*",
          "versionEndIncluding" : "1.5.0"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:H/Au:N/C:P/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "HIGH",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 4.9,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2006-02-09T02:02Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0618",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "qnx",
            "product" : {
              "product_data" : [ {
                "product_name" : "neutrino_rtos",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.3.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18750",
          "name" : "18750",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1015599",
          "name" : "1015599",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.idefense.com/intelligence/vulnerabilities/display.php?id=380",
          "name" : "20060207 QNX Neutrino RTOS fontsleuth Command Format String Vulnerability",
          "refsource" : "IDEFENSE",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/22966",
          "name" : "22966",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16539",
          "name" : "16539",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0474",
          "name" : "ADV-2006-0474",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24559",
          "name" : "qnx-fontsleuth-format-string(24559)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Format string vulnerability in fontsleuth in QNX Neutrino RTOS 6.3.0 allows local users to execute arbitrary code via format string specifiers in the zeroth argument (program name)."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:qnx:neutrino_rtos:6.3.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 4.6
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 3.9,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-09T02:02Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0619",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "qnx",
            "product" : {
              "product_data" : [ {
                "product_name" : "rtos",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.3.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18750",
          "name" : "18750",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1015599",
          "name" : "1015599",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.idefense.com/intelligence/vulnerabilities/display.php?id=381",
          "name" : "20060207 QNX Neutrino RTOS libAp ABLPATH Buffer Overflow Vulnerability",
          "refsource" : "IDEFENSE",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.idefense.com/intelligence/vulnerabilities/display.php?id=382",
          "name" : "20060207 QNX Neutrino RTOS libph PHOTON_PATH Buffer Overflow Vulnerability",
          "refsource" : "IDEFENSE",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/22964",
          "name" : "22964",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/22965",
          "name" : "22965",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16539",
          "name" : "16539",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0474",
          "name" : "ADV-2006-0474",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24557",
          "name" : "qnx-libph-bo(24557)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24558",
          "name" : "qnx-libap-bo(24558)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple stack-based buffer overflows in QNX Neutrino RTOS 6.3.0 allow local users to execute arbitrary code via long (1) ABLPATH or (2) ABLANG environment variables in the libAP library (libAp.so.2) or (3) a long PHOTON_PATH environment variable to the setitem function in the libph library."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:qnx:rtos:6.3.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 4.6
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 3.9,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-09T02:02Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0620",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "qnx",
            "product" : {
              "product_data" : [ {
                "product_name" : "rtos",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.2.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.2.1a",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.2.1b",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18750",
          "name" : "18750",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1015599",
          "name" : "1015599",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.idefense.com/intelligence/vulnerabilities/display.php?id=383",
          "name" : "20060207 QNX Neutrino RTOS phfont Race Condition Vulnerability",
          "refsource" : "IDEFENSE",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/22963",
          "name" : "22963",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16539",
          "name" : "16539",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0474",
          "name" : "ADV-2006-0474",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24555",
          "name" : "qnx-phfont-race-condition(24555)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Race condition in phfont in QNX Neutrino RTOS 6.2.1 allows local users to execute arbitrary code via unspecified manipulations of the PHFONT and PHOTON2_PATH environment variables."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:qnx:rtos:6.2.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:qnx:rtos:6.2.1a:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:qnx:rtos:6.2.1b:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:H/Au:N/C:C/I:C/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "HIGH",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 6.2
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 1.9,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-09T02:02Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0621",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "qnx",
            "product" : {
              "product_data" : [ {
                "product_name" : "rtos",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.2.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18750",
          "name" : "18750",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1015599",
          "name" : "1015599",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.idefense.com/intelligence/vulnerabilities/display.php?id=385",
          "name" : "20060207 QNX Neutrino RTOS su Command Buffer Overflow",
          "refsource" : "IDEFENSE",
          "tags" : [ ]
        }, {
          "url" : "http://www.idefense.com/intelligence/vulnerabilities/display.php?id=388",
          "name" : "20060207 QNX Neutrino RTOS passwd Command Buffer Overflow",
          "refsource" : "IDEFENSE",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/22959",
          "name" : "22959",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/22961",
          "name" : "22961",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16539",
          "name" : "16539",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0474",
          "name" : "ADV-2006-0474",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24551",
          "name" : "qnx-passwd-bo(24551)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24554",
          "name" : "qnx-su-bo(24554)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple buffer overflows in QNX Neutrino RTOS 6.2.0 allow local users to execute arbitrary code via a long first argument to the (1) su or (2) passwd commands."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:qnx:rtos:6.2.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.2
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 3.9,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-09T02:02Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0622",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "qnx",
            "product" : {
              "product_data" : [ {
                "product_name" : "rtos",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.3.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-399"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18750",
          "name" : "18750",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1015598",
          "name" : "1015598",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.idefense.com/intelligence/vulnerabilities/display.php?id=386",
          "name" : "20060207 QNX RTOS 6.3.0 Local Denial of Service Vulnerability",
          "refsource" : "IDEFENSE",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/22960",
          "name" : "22960",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16539",
          "name" : "16539",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0474",
          "name" : "ADV-2006-0474",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24553",
          "name" : "qnx-gdb-dos(24553)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "QNX Neutrino RTOS 6.3.0 allows local users to cause a denial of service (hang) by supplying a \"break *0xb032d59f\" command to gdb."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:qnx:rtos:6.3.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:N/I:N/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 4.9
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 3.9,
        "impactScore" : 6.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-09T02:02Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0623",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "qnx",
            "product" : {
              "product_data" : [ {
                "product_name" : "rtos",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.3.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18750",
          "name" : "18750",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1015598",
          "name" : "1015598",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.idefense.com/intelligence/vulnerabilities/display.php?id=387",
          "name" : "20060207 QNX RTOS 6.3.0 rc.local Insecure File Permissions Vulnerability",
          "refsource" : "IDEFENSE",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/22958",
          "name" : "22958",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16539",
          "name" : "16539",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0474",
          "name" : "ADV-2006-0474",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24552",
          "name" : "qnx-rclocal-root-privileges(24552)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "QNX Neutrino RTOS 6.3.0 ships /etc/rc.d/rc.local with world-writable permissions, which allows local users to modify the file and execute arbitrary code at system startup."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:qnx:rtos:6.3.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.2
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 3.9,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-09T02:02Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0624",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "webeveyn",
            "product" : {
              "product_data" : [ {
                "product_name" : "whomp_real_estate_manager_xp_2005",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18780",
          "name" : "18780",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/418",
          "name" : "418",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/22969",
          "name" : "22969",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/424389/100/0/threaded",
          "name" : "20060208 Whomp Real Estate Manager XP 2005 Sql Injection",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16544",
          "name" : "16544",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0489",
          "name" : "ADV-2006-0489",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24592",
          "name" : "whomp-login-sql-injection(24592)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in check.asp in Whomp Real Estate Manager XP 2005 allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:webeveyn:whomp_real_estate_manager_xp_2005:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-09T02:02Z",
    "lastModifiedDate" : "2018-10-19T15:45Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0625",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "spip",
            "product" : {
              "product_data" : [ {
                "product_name" : "spip",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.8.2d",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.8.2e",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.8.2g",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://retrogod.altervista.org/spip_182g_shell_inj_xpl.html",
          "name" : "http://retrogod.altervista.org/spip_182g_shell_inj_xpl.html",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://secunia.com/advisories/18676",
          "name" : "18676",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1015602",
          "name" : "1015602",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/23086",
          "name" : "23086",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16556",
          "name" : "16556",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0483",
          "name" : "ADV-2006-0483",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24600",
          "name" : "spip-rss-file-include(24600)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Directory traversal vulnerability in Spip_RSS.PHP in SPIP 1.8.2g and earlier allows remote attackers to read or include arbitrary files via \"..\"  sequences in the GLOBALS[type_urls] parameter, which could then be used to execute arbitrary code via resultant direct static code injection in the file parameter to spip_acces_doc.php3."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:spip:spip:1.8.2d:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:spip:spip:1.8.2e:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:spip:spip:1.8.2g:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 6.4
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-09T18:06Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0626",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "spip",
            "product" : {
              "product_data" : [ {
                "product_name" : "spip",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.8.2g",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://retrogod.altervista.org/spip_182g_shell_inj_xpl.html",
          "name" : "http://retrogod.altervista.org/spip_182g_shell_inj_xpl.html",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://secunia.com/advisories/18676",
          "name" : "18676",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1015602",
          "name" : "1015602",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/23087",
          "name" : "23087",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16551",
          "name" : "16551",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0483",
          "name" : "ADV-2006-0483",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24599",
          "name" : "spip-access-doc-sql-injection(24599)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in spip_acces_doc.php3 in SPIP 1.8.2g and earlier allows remote attackers to execute arbitrary SQL commands via the file parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:spip:spip:1.8.2g:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-09T18:06Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0627",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "clever_copy",
            "product" : {
              "product_data" : [ {
                "product_name" : "clever_copy",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0a",
                    "version_affected" : "="
                  }, {
                    "version_value" : "23.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18790",
          "name" : "18790",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.evuln.com/vulns/64/summary.html",
          "name" : "http://www.evuln.com/vulns/64/summary.html",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/424831/100/0/threaded",
          "name" : "20060212 [eVuln] Clever Copy 'Referer' & 'X-Forwarded-For' XSS Vulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16607",
          "name" : "16607",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0495",
          "name" : "ADV-2006-0495",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24524",
          "name" : "clevercopy-script-xss(24524)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in Clever Copy 2.0, 2.0a, and 3.0 allows remote attackers to inject arbitrary web script or HTML via the (1) Referer or (2) X-Forwarded-For headers in an HTTP request, which are not properly handled when the administrator accesses Site Stats."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clever_copy:clever_copy:2.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clever_copy:clever_copy:2.0a:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clever_copy:clever_copy:23.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-09T19:06Z",
    "lastModifiedDate" : "2018-10-19T15:45Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0628",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "dale_ray",
            "product" : {
              "product_data" : [ {
                "product_name" : "myquiz",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.01",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://attrition.org/pipermail/vim/2006-February/000537.html",
          "name" : "20060209 Vendor ACK for MyQuiz",
          "refsource" : "VIM",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18737",
          "name" : "18737",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/409",
          "name" : "409",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.corantodemo.net/coranto/viewnews.cgi?id=EpApAAAVkyirPGThSf&style=dldetails",
          "name" : "http://www.corantodemo.net/coranto/viewnews.cgi?id=EpApAAAVkyirPGThSf&style=dldetails",
          "refsource" : "MISC",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.evuln.com/vulns/57/summary.html",
          "name" : "http://www.evuln.com/vulns/57/summary.html",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/22925",
          "name" : "22925",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/423921/100/0/threaded",
          "name" : "20060203 [eVuln] MyQuiz Arbitrary Command Execution Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/424266/100/0/threaded",
          "name" : "20060207 MyQuiz Arbitrary Command Execution Exploit (perl)",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0443",
          "name" : "ADV-2006-0443",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24501",
          "name" : "myquiz-pathinfo-command-execution(24501)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "myquiz.pl in Dale Ray MyQuiz 1.01 allows remote attackers to execute arbitrary commands via shell metacharacters in the URL, which are not properly handled as part of the PATH_INFO environment variable."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:dale_ray:myquiz:1.01:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-10T11:02Z",
    "lastModifiedDate" : "2018-10-19T15:45Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0629",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "aol",
            "product" : {
              "product_data" : [ {
                "product_name" : "instant_messenger",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.9.3861",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://archives.neohapsis.com/archives/fulldisclosure/2006-01/0948.html",
          "name" : "20060129 AOL Instant Messenger 5.9.3861 Local Buffer Overrun Vulnerability",
          "refsource" : "FULLDISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/423906/100/0/threaded",
          "name" : "20060203 AOL Instant Messenger Version 5.9.3861 Local Buffer Overrun Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/423920/100/0/threaded",
          "name" : "20060203 Re: AOL Instant Messenger Version 5.9.3861 Local Buffer Overrun Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24362",
          "name" : "aim-buddy-info-bo(24362)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in AOL Instant Messenger (AIM) 5.9.3861 allows user-assisted remote attackers to cause a denial of service (client crash) and possibly execute arbitrary code by tricking the user into requesting Buddy Info about a long screen name, which might cause a buffer overflow."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:aol:instant_messenger:5.9.3861:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:H/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "HIGH",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.1
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 4.9,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2006-02-10T11:02Z",
    "lastModifiedDate" : "2018-10-19T15:45Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0630",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ritlabs",
            "product" : {
              "product_data" : [ {
                "product_name" : "the_bat",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.0.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.0.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.0.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.0.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.0.14",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.grok.org.uk/pipermail/full-disclosure/2006-February/041973.html",
          "name" : "20060206 SECURITY.NNOV: The Bat! 2.x message headers spoofing",
          "refsource" : "FULLDISC",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18713",
          "name" : "18713",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.security.nnov.ru/advisories/thebatspoof.asp",
          "name" : "http://www.security.nnov.ru/advisories/thebatspoof.asp",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/424129/100/0/threaded",
          "name" : "20060206 SECURITY.NNOV: The Bat! 2.x message headers spoofing",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16515",
          "name" : "16515",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24535",
          "name" : "thebat-message-header-spoofing(24535)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.ritlabs.com/bt/bug_view_advanced_page.php?bug_id=0003029",
          "name" : "https://www.ritlabs.com/bt/bug_view_advanced_page.php?bug_id=0003029",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "RITLabs The Bat! before 3.0.0.15 displays certain important headers from encapsulated data in message/partial MIME messages, instead of the real headers, which is in violation of RFC2046 header merging rules and allows remote attackers to spoof the origin of e-mail by sending a fragmented message, as demonstrated using spoofed Received: and Message-ID: headers."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ritlabs:the_bat:3.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ritlabs:the_bat:3.0.0.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ritlabs:the_bat:3.0.0.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ritlabs:the_bat:3.0.0.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ritlabs:the_bat:3.0.0.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ritlabs:the_bat:3.0.0.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ritlabs:the_bat:3.0.0.12:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ritlabs:the_bat:3.0.0.14:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-10T11:02Z",
    "lastModifiedDate" : "2018-10-19T15:45Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0631",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "erik_c._thauvin",
            "product" : {
              "product_data" : [ {
                "product_name" : "mailback",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://seclists.org/lists/bugtraq/2006/Feb/0094.html",
          "name" : "20060205 mailback script exploit",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://seclists.org/lists/bugtraq/2006/Feb/0154.html",
          "name" : "20060210 Re: mailback script exploit",
          "refsource" : "BUGTRAQ",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://secunia.com/advisories/18748",
          "name" : "18748",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://vc.thauvin.net/cvs/cgi/mailback/mailback.pl?view=log",
          "name" : "http://vc.thauvin.net/cvs/cgi/mailback/mailback.pl?view=log",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/22955",
          "name" : "22955",
          "refsource" : "OSVDB",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0459",
          "name" : "ADV-2006-0459",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24540",
          "name" : "mailback-mail-relay(24540)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "CRLF injection vulnerability in mailback.pl in Erik C. Thauvin mailback allows remote attackers to use mailback as a \"spam proxy\" by modifying mail headers, including recipient e-mail addresses, via newline characters in the Subject field."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:erik_c._thauvin:mailback:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-10T11:02Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0632",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "phpbb_group",
            "product" : {
              "product_data" : [ {
                "product_name" : "phpbb",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.6c",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.6d",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.7a",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.8a",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.16",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.17",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.18",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.19",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0_beta1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0_rc1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0_rc2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0_rc3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0_rc4",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18727",
          "name" : "18727",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/22949",
          "name" : "22949",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.r-security.net/tutorials/view/readtutorial.php?id=4",
          "name" : "http://www.r-security.net/tutorials/view/readtutorial.php?id=4",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/424074/100/0/threaded",
          "name" : "20060205 Easily exploitable Pseudo Random Number generator in phpbb version 2.0.19 and under.",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0461",
          "name" : "ADV-2006-0461",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24573",
          "name" : "phpbb-weak-rnd(24573)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The gen_rand_string function in phpBB 2.0.19 uses insufficiently random data (small value space) to create the activation key (\"validation ID\") that is sent by e-mail when establishing a password, which makes it easier for remote attackers to obtain the key and modify passwords for existing accounts or create new accounts."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:phpbb_group:phpbb:2.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:phpbb_group:phpbb:2.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:phpbb_group:phpbb:2.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:phpbb_group:phpbb:2.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:phpbb_group:phpbb:2.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:phpbb_group:phpbb:2.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:phpbb_group:phpbb:2.0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:phpbb_group:phpbb:2.0.6c:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:phpbb_group:phpbb:2.0.6d:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:phpbb_group:phpbb:2.0.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:phpbb_group:phpbb:2.0.7a:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:phpbb_group:phpbb:2.0.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:phpbb_group:phpbb:2.0.8a:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:phpbb_group:phpbb:2.0.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:phpbb_group:phpbb:2.0.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:phpbb_group:phpbb:2.0.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:phpbb_group:phpbb:2.0.12:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:phpbb_group:phpbb:2.0.13:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:phpbb_group:phpbb:2.0.14:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:phpbb_group:phpbb:2.0.15:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:phpbb_group:phpbb:2.0.16:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:phpbb_group:phpbb:2.0.17:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:phpbb_group:phpbb:2.0.18:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:phpbb_group:phpbb:2.0.19:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:phpbb_group:phpbb:2.0_beta1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:phpbb_group:phpbb:2.0_rc1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:phpbb_group:phpbb:2.0_rc2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:phpbb_group:phpbb:2.0_rc3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:phpbb_group:phpbb:2.0_rc4:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 6.4
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-10T11:02Z",
    "lastModifiedDate" : "2018-10-19T15:45Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0633",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "invisionpower",
            "product" : {
              "product_data" : [ {
                "product_name" : "invision_power_board",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.1.4",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-287"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://forums.invisionpower.com/lofiversion/index.php/t200085.html",
          "name" : "http://forums.invisionpower.com/lofiversion/index.php/t200085.html",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.r-security.net/tutorials/view/readtutorial.php?id=4",
          "name" : "http://www.r-security.net/tutorials/view/readtutorial.php?id=4",
          "refsource" : "MISC",
          "tags" : [ "Patch" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The make_password function in ipsclass.php in Invision Power Board (IPB) 2.1.4 uses random data generated from partially predictable seeds to create the authentication code that is sent by e-mail to a user with a lost password, which might make it easier for remote attackers to guess the code and change the password for an IPB account, possibly involving millions of requests."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:invisionpower:invision_power_board:2.1.4:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 6.4
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-10T11:02Z",
    "lastModifiedDate" : "2013-01-03T05:00Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0634",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "borland_software",
            "product" : {
              "product_data" : [ {
                "product_name" : "c++_builder",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://securitytracker.com/id?1015588",
          "name" : "1015588",
          "refsource" : "SECTRACK",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/22953",
          "name" : "22953",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/424085/100/0/threaded",
          "name" : "20060206 [xfocus-SD-060206]BCB compiler incorrect deal sizeof operator vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.xfocus.net/releases/200602/a849.html",
          "name" : "http://www.xfocus.net/releases/200602/a849.html",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24514",
          "name" : "bcb-compiler-integer-overflow(24514)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Borland C++Builder 6 (BCB6) with Update Pack 4 Enterprise edition (ent_upd4) evaluates the \"i>sizeof(int)\" expression to false when i equals -1, which might introduce integer overflow vulnerabilities into applications that could be exploited by context-dependent attackers."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:borland_software:c\\+\\+_builder:6:enterprise_update_4:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 4.6
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 3.9,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-10T11:02Z",
    "lastModifiedDate" : "2018-10-19T15:45Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0635",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "fabrice_bellard",
            "product" : {
              "product_data" : [ {
                "product_name" : "tiny_c_compiler",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.9.23",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.osvdb.org/22956",
          "name" : "22956",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/424257/100/0/threaded",
          "name" : "20060207 Re: [xfocus-SD-060206]BCB compiler incorrect deal sizeof operator vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Tiny C Compiler (TCC) 0.9.23 (aka TinyCC) evaluates the \"i>sizeof(int)\" expression to false when i equals -1, which might introduce integer overflow vulnerabilities into applications that could be exploited by context-dependent attackers."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:fabrice_bellard:tiny_c_compiler:0.9.23:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 4.6
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 3.9,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-10T11:02Z",
    "lastModifiedDate" : "2018-10-19T15:45Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0636",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "eyeos_project",
            "product" : {
              "product_data" : [ {
                "product_name" : "eyeos",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8.1_r1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8.2_r1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8.2_r2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8.2_r3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8.3_r1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8.3_r2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8.4_r1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8.5_r1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8.9",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18757",
          "name" : "18757",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/419",
          "name" : "419",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1015609",
          "name" : "1015609",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.gulftech.org/?node=research&article_id=00096-02072006",
          "name" : "http://www.gulftech.org/?node=research&article_id=00096-02072006",
          "refsource" : "MISC",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/424329/100/0/threaded",
          "name" : "20060207 eyeOS <= 0.8.9 Remote Code Execution",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16537",
          "name" : "16537",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0466",
          "name" : "ADV-2006-0466",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24569",
          "name" : "eyeos-desktop-file-include(24569)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "desktop.php in eyeOS 0.8.9 and earlier tests for the existence of the _SESSION variable before calling the session_start function, which allows remote attackers to execute arbitrary PHP code and possibly conduct other attacks by modifying critical assumed-immutable variables, as demonstrated using PHP code in the _SESSION[apps][eyeOptions.eyeapp][wrapup] variable."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:eyeos_project:eyeos:0.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:eyeos_project:eyeos:0.8.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:eyeos_project:eyeos:0.8.1_r1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:eyeos_project:eyeos:0.8.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:eyeos_project:eyeos:0.8.2_r1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:eyeos_project:eyeos:0.8.2_r2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:eyeos_project:eyeos:0.8.2_r3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:eyeos_project:eyeos:0.8.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:eyeos_project:eyeos:0.8.3_r1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:eyeos_project:eyeos:0.8.3_r2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:eyeos_project:eyeos:0.8.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:eyeos_project:eyeos:0.8.4_r1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:eyeos_project:eyeos:0.8.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:eyeos_project:eyeos:0.8.5_r1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:eyeos_project:eyeos:0.8.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:eyeos_project:eyeos:0.8.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:eyeos_project:eyeos:0.8.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:eyeos_project:eyeos:0.8.9:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-10T11:02Z",
    "lastModifiedDate" : "2018-10-19T15:45Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0637",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "qualcomm",
            "product" : {
              "product_data" : [ {
                "product_name" : "eudora_worldmail",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/archive/1/424157/100/0/threaded",
          "name" : "20060204 (OLD) Eudora WorldMail 3.0 Windows 2000 Remote System Exploit",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Buffer overflow in cram.dll in QUALCOMM Eudora WorldMail 3.0 allows remote attackers to execute arbitrary code via an IMAP APPEND command with a long message literal argument, as demonstrated by Worldmail.pl. NOTE: this is a different vector and a different manipulation than CVE-2005-4267, so it might be a different vulnerability than CVE-2005-4267."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:qualcomm:eudora_worldmail:3.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-10T11:02Z",
    "lastModifiedDate" : "2018-10-19T15:45Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0638",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "mybulletinboard",
            "product" : {
              "product_data" : [ {
                "product_name" : "mybulletinboard",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0.3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://myimei.com/security/2006-02-07/mybb103moderationphpsqlinject-while-merging-posts.html",
          "name" : "http://myimei.com/security/2006-02-07/mybb103moderationphpsqlinject-while-merging-posts.html",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18754",
          "name" : "18754",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/22957",
          "name" : "22957",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/424335/100/0/threaded",
          "name" : "20060207 [myimei]MyBB1.0.3~moderation.php~SqlInject while merging posts",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16538",
          "name" : "16538",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0475",
          "name" : "ADV-2006-0475",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in moderation.php in MyBB (aka MyBulletinBoard) 1.0.3 allows remote authenticated users, with certain privileges for moderating and merging posts, to execute arbitrary SQL commands via the posts parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mybulletinboard:mybulletinboard:1.0.3:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.5
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-10T11:02Z",
    "lastModifiedDate" : "2018-10-19T15:45Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0639",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "mybulletinboard",
            "product" : {
              "product_data" : [ {
                "product_name" : "mybulletinboard",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://myimei.com/security/2006-01-14/mybb-102searchphpxss-attackandmore.html",
          "name" : "http://myimei.com/security/2006-01-14/mybb-102searchphpxss-attackandmore.html",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/424334/100/0/threaded",
          "name" : "20060207 [myimei]MyBB 1.0.2 XSS attack in search.php",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/424375/100/0/threaded",
          "name" : "20060208 Re: [myimei]MyBB 1.0.2 XSS attack in search.php",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24466",
          "name" : "mybb-search-xss(24466)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in search.php in MyBB (aka MyBulletinBoard) 1.0.2 allows remote attackers with knowledge of the table prefix to inject arbitrary web script or HTML via a URL encoded value of the keywords parameter, as demonstrated by %3Cscript%3E."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mybulletinboard:mybulletinboard:1.0.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-10T11:02Z",
    "lastModifiedDate" : "2018-10-19T15:45Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0640",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "orbicule",
            "product" : {
              "product_data" : [ {
                "product_name" : "undercover",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/archive/1/423955/100/0/threaded",
          "name" : "20060202 Issues with security software: orbicule.com \"Undercover\"",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Orbicule Undercover allows attackers with physical or root access to disable the protection by using the chmod command to change the permissions of the /private/etc/uc.app/Contents/MacOS/uc file, which prevents the service from being started in LaunchDaemon."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:orbicule:undercover:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:N/I:P/A:N",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 2.1
        },
        "severity" : "LOW",
        "exploitabilityScore" : 3.9,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-10T11:02Z",
    "lastModifiedDate" : "2018-10-19T15:45Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0641",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "orbicule",
            "product" : {
              "product_data" : [ {
                "product_name" : "undercover",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/archive/1/423955/100/0/threaded",
          "name" : "20060202 Issues with security software: orbicule.com \"Undercover\"",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Orbicule Undercover uses a third-party web server to determine the IP address through which the computer is accessing the Internet, but does not document this third-party disclosure, which leads to a potential privacy leak that might allow transmission of sensitive information to an unintended remote destination."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:orbicule:undercover:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:H/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "HIGH",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 2.6
        },
        "severity" : "LOW",
        "exploitabilityScore" : 4.9,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2006-02-10T11:02Z",
    "lastModifiedDate" : "2018-10-19T15:45Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0642",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "trend_micro",
            "product" : {
              "product_data" : [ {
                "product_name" : "interscan_messaging_security_suite",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "interscan_web_security_suite",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "serverprotect",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.58",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.packetstormsecurity.org/0602-advisories/Bypass.pdf",
          "name" : "http://www.packetstormsecurity.org/0602-advisories/Bypass.pdf",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.packetstormsecurity.org/filedesc/Bypass.pdf.html",
          "name" : "http://www.packetstormsecurity.org/filedesc/Bypass.pdf.html",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/423896/100/0/threaded",
          "name" : "20060203 Trend Micro ServerProtect version 5.58 can be easily circumvented via the mechanism that limits how many files to scan.",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/423913/100/0/threaded",
          "name" : "20060203 Re: Trend Micro ServerProtect version 5.58 can be easily circumvented via the mechanism that limits how many files to scan.",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/423914/100/0/threaded",
          "name" : "20060203 Re: Trend Micro ServerProtect version 5.58 can be easily circumvented via the mechanism that limits how many files to scan.",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/424172/100/0/threaded",
          "name" : "20060205 RE: Trend Micro ServerProtect version 5.58 can be easily circumvented via the mechanism that limits how many files to scan.",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/424598/100/0/threaded",
          "name" : "20060206 Fwd: Trend Micro ServerProtect version 5.58 can be easily circumvented via the mechanism that limits how many files to scan.",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16483",
          "name" : "16483",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24658",
          "name" : "serverprotect-file-scanning-bypass(24658)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Trend Micro ServerProtect 5.58, and possibly InterScan Messaging Security Suite and InterScan Web Security Suite, have a default configuration setting of \"Do not scan compressed files when Extracted file count exceeds 500 files,\" which may be too low in certain circumstances, which allows remote attackers to bypass anti-virus checks by sending compressed archives containing many small files. NOTE: since this is related to a configuration setting that has an operational impact that might vary depending on the environment, and the product is claimed to report a message when the compressed file exceeds specified limits, perhaps this should not be included in CVE."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:trend_micro:interscan_messaging_security_suite:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:trend_micro:interscan_web_security_suite:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:trend_micro:serverprotect:5.58:*:emc:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:H/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "HIGH",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.1
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 4.9,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2006-02-10T11:02Z",
    "lastModifiedDate" : "2018-10-19T15:45Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0643",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "wiredred",
            "product" : {
              "product_data" : [ {
                "product_name" : "e_pop_web_conferencing",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.1.0.755",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18753",
          "name" : "18753",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/421",
          "name" : "421",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/22997",
          "name" : "22997",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/424419/100/0/threaded",
          "name" : "20060208 WiredRed EPOP XSS Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16542",
          "name" : "16542",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0505",
          "name" : "ADV-2006-0505",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24609",
          "name" : "epop-topic-xss(24609)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in WiredRed e/pop Web Conferencing 4.1.0.755 allows remote authenticated users to inject arbitrary web script or HTML via the topic name of a conference."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wiredred:e_pop_web_conferencing:4.1.0.755:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-10T11:02Z",
    "lastModifiedDate" : "2018-10-19T15:45Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0644",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "cpg-nuke",
            "product" : {
              "product_data" : [ {
                "product_name" : "dragonfly_cms",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9.0.6_.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://dragonflycms.org/Forums/viewtopic/p=98034.html",
          "name" : "http://dragonflycms.org/Forums/viewtopic/p=98034.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://dragonflycms.org/Forums/viewtopic/p=98034.html#98034",
          "name" : "http://dragonflycms.org/Forums/viewtopic/p=98034.html#98034",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://retrogod.altervista.org/dragonfly9.0.6.1_incl_xpl.html",
          "name" : "http://retrogod.altervista.org/dragonfly9.0.6.1_incl_xpl.html",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://securitytracker.com/id?1015601",
          "name" : "1015601",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/23058",
          "name" : "23058",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/424439/100/0/threaded",
          "name" : "20060208 CPGNuke Dragonfly 9.0.6.1 remote commands execution through arbitrary local inclusion",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16546",
          "name" : "16546",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24660",
          "name" : "cpg-dragonfly-file-include(24660)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple directory traversal vulnerabilities in install.php in CPG-Nuke Dragonfly CMS (aka CPG Dragonfly CMS) 9.0.6.1 allow remote attackers to include and execute arbitrary local files via directory traversal sequences and a NUL (%00) character in (1) the newlang parameter and (2) the installlang parameter in a cookie, as demonstrated by using error.php to insert malicious code into a log file, or uploading a malicious .png file, which is then included using install.php."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cpg-nuke:dragonfly_cms:9.0.6_.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-10T11:02Z",
    "lastModifiedDate" : "2018-10-19T15:45Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0645",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "free_software_foundation_inc.",
            "product" : {
              "product_data" : [ {
                "product_name" : "libtasn1",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.2.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.2.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.2.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.2.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.2.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.2.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.2.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.2.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.2.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.2.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.2.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.2.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.2.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.2.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.2.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.2.16",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.2.17",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://josefsson.org/cgi-bin/viewcvs.cgi/gnutls/tests/certder.c?view=markup",
          "name" : "http://josefsson.org/cgi-bin/viewcvs.cgi/gnutls/tests/certder.c?view=markup",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://josefsson.org/cgi-bin/viewcvs.cgi/libtasn1/NEWS?root=gnupg-mirror&view=markup",
          "name" : "http://josefsson.org/cgi-bin/viewcvs.cgi/libtasn1/NEWS?root=gnupg-mirror&view=markup",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://josefsson.org/gnutls/releases/libtasn1/libtasn1-0.2.18-from-0.2.17.patch",
          "name" : "http://josefsson.org/gnutls/releases/libtasn1/libtasn1-0.2.18-from-0.2.17.patch",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://lists.gnupg.org/pipermail/gnutls-dev/2006-February/001058.html",
          "name" : "[gnutls-dev] 20060209 Libtasn1 0.2.18 - Tiny ASN.1 Library - Security release",
          "refsource" : "MLIST",
          "tags" : [ ]
        }, {
          "url" : "http://lists.gnupg.org/pipermail/gnutls-dev/2006-February/001059.html",
          "name" : "[gnutls-dev] 20060209 GnuTLS 1.2.10 - Security release",
          "refsource" : "MLIST",
          "tags" : [ ]
        }, {
          "url" : "http://lists.gnupg.org/pipermail/gnutls-dev/2006-February/001060.html",
          "name" : "[gnutls-dev] 20060209 GnuTLS 1.3.4 - Experimental - Security release",
          "refsource" : "MLIST",
          "tags" : [ ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2006-0207.html",
          "name" : "RHSA-2006:0207",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18794",
          "name" : "18794",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18815",
          "name" : "18815",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18830",
          "name" : "18830",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18832",
          "name" : "18832",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18898",
          "name" : "18898",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18918",
          "name" : "18918",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/19080",
          "name" : "19080",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/19092",
          "name" : "19092",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/446",
          "name" : "446",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1015612",
          "name" : "1015612",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2006/dsa-985",
          "name" : "DSA-985",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2006/dsa-986",
          "name" : "DSA-986",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.gentoo.org/security/en/glsa/glsa-200602-08.xml",
          "name" : "GLSA-200602-08",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://www.gleg.net/protover_ssl.shtml",
          "name" : "http://www.gleg.net/protover_ssl.shtml",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDKSA-2006:039",
          "name" : "MDKSA-2006:039",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/23054",
          "name" : "23054",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/archives/fedora-announce-list/2006-February/msg00043.html",
          "name" : "FEDORA-2006-107",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/424538/100/0/threaded",
          "name" : "20060209 ProtoVer SSL: GnuTLS",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16568",
          "name" : "16568",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.trustix.org/errata/2006/0008",
          "name" : "2006-0008",
          "refsource" : "TRUSTIX",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0496",
          "name" : "ADV-2006-0496",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24606",
          "name" : "gnutls-libtasn1-der-dos(24606)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10540",
          "name" : "oval:org.mitre.oval:def:10540",
          "refsource" : "OVAL",
          "tags" : [ ]
        }, {
          "url" : "https://usn.ubuntu.com/251-1/",
          "name" : "USN-251-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Tiny ASN.1 Library (libtasn1) before 0.2.18, as used by (1) GnuTLS 1.2.x before 1.2.10 and 1.3.x before 1.3.4, and (2) GNU Shishi, allows attackers to crash the DER decoder and possibly execute arbitrary code via \"out-of-bounds access\" caused by invalid input, as demonstrated by the ProtoVer SSL test suite."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:free_software_foundation_inc.:libtasn1:0.1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:free_software_foundation_inc.:libtasn1:0.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:free_software_foundation_inc.:libtasn1:0.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:free_software_foundation_inc.:libtasn1:0.2.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:free_software_foundation_inc.:libtasn1:0.2.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:free_software_foundation_inc.:libtasn1:0.2.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:free_software_foundation_inc.:libtasn1:0.2.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:free_software_foundation_inc.:libtasn1:0.2.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:free_software_foundation_inc.:libtasn1:0.2.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:free_software_foundation_inc.:libtasn1:0.2.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:free_software_foundation_inc.:libtasn1:0.2.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:free_software_foundation_inc.:libtasn1:0.2.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:free_software_foundation_inc.:libtasn1:0.2.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:free_software_foundation_inc.:libtasn1:0.2.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:free_software_foundation_inc.:libtasn1:0.2.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:free_software_foundation_inc.:libtasn1:0.2.12:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:free_software_foundation_inc.:libtasn1:0.2.13:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:free_software_foundation_inc.:libtasn1:0.2.14:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:free_software_foundation_inc.:libtasn1:0.2.15:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:free_software_foundation_inc.:libtasn1:0.2.16:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:free_software_foundation_inc.:libtasn1:0.2.17:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-10T18:06Z",
    "lastModifiedDate" : "2018-10-19T15:45Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0646",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "suse",
            "product" : {
              "product_data" : [ {
                "product_name" : "suse_linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.suse.com/archive/suse-security-announce/2006-Feb/0003.html",
          "name" : "SUSE-SA:2006:007",
          "refsource" : "SUSE",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18811",
          "name" : "18811",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16581",
          "name" : "16581",
          "refsource" : "BID",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "ld in SUSE Linux 9.1 through 10.0, and SLES 9, in certain circumstances when linking binaries, can leave an empty RPATH or RUNPATH, which allows local attackers to execute arbitrary code as other users via by running an ld-linked application from the current directory, which could contain an attacker-controlled library file."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:suse:suse_linux:9.0:*:enterprise_server:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:suse:suse_linux:9.1:*:personal:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:suse:suse_linux:9.1:*:professional:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:suse:suse_linux:9.1:*:x86_64:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:suse:suse_linux:9.2:*:personal:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:suse:suse_linux:9.2:*:professional:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:suse:suse_linux:9.2:*:x86_64:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:suse:suse_linux:9.3:*:personal:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:suse:suse_linux:9.3:*:professional:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:suse:suse_linux:9.3:*:x86_64:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:suse:suse_linux:10.0:*:professional:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "LOCAL",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 4.4
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 3.4,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-11T11:02Z",
    "lastModifiedDate" : "2008-09-05T20:59Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0647",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "sun",
            "product" : {
              "product_data" : [ {
                "product_name" : "java_system_directory_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.immunitysec.com/pipermail/dailydave/2006-February/002914.html",
          "name" : "[Dailydave] 20060208 Sun Directory Server 5.2 fun",
          "refsource" : "MLIST",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://lists.immunitysec.com/pipermail/dailydave/2006-February/002916.html",
          "name" : "[Dailydave] 20060210 ??? Sun Directory Server 5.2 fun ???",
          "refsource" : "MLIST",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18769",
          "name" : "18769",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1015604",
          "name" : "1015604",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://sunsolve.sun.com/search/document.do?assetkey=1-26-102294-1",
          "name" : "102294",
          "refsource" : "SUNALERT",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16550",
          "name" : "16550",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0492",
          "name" : "ADV-2006-0492",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24605",
          "name" : "sun-java-ldap-dos(24605)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "LDAP service in Sun Java System Directory Server 5.2, running on Linux and possibly other platforms, allows remote attackers to cause a denial of service (memory allocation error) via an LDAP packet with a crafted subtree search request, as demonstrated using the ProtoVer LDAP test suite."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sun:java_system_directory_server:5.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-13T11:06Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0648",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "php_icalendar",
            "product" : {
              "product_data" : [ {
                "product_name" : "php_icalendar",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://evuln.com/vulns/70/summary.html",
          "name" : "http://evuln.com/vulns/70/summary.html",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://phpicalendar.net/forums/viewtopic.php?t=396",
          "name" : "http://phpicalendar.net/forums/viewtopic.php?t=396",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18778",
          "name" : "18778",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/420",
          "name" : "420",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/424424/100/0/threaded",
          "name" : "20060208 [eVuln] PHP iCalendar File Inclusion Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16557",
          "name" : "16557",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0493",
          "name" : "ADV-2006-0493",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24591",
          "name" : "phpicalendar-template-search-file-include(24591)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple directory traversal vulnerabilities in PHP iCalendar 2.0.1, 2.1, and 2.2 allow remote attackers to include arbitrary files via the (1) getdate and possibly other parameters used in the replace_files function in search.php and (2) $file variable as used in the parse function in functions/template.php."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php_icalendar:php_icalendar:2.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php_icalendar:php_icalendar:2.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:php_icalendar:php_icalendar:2.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-13T11:06Z",
    "lastModifiedDate" : "2018-10-19T15:45Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0649",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "dataparksearch",
            "product" : {
              "product_data" : [ {
                "product_name" : "dataparksearch",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.16",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.17",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.18",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.19",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.20",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.21",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.22",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.23",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.24",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.25",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.26",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.27",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.28",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.29",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.30",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.31",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.32",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.33",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.34",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.35",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.36",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18751",
          "name" : "18751",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.dataparksearch.org/ChangeLog",
          "name" : "http://www.dataparksearch.org/ChangeLog",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16572",
          "name" : "16572",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0488",
          "name" : "ADV-2006-0488",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24627",
          "name" : "dataparksearch-scripts-xss(24627)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in DataparkSearch before 4.37 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:dataparksearch:dataparksearch:4.16:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:dataparksearch:dataparksearch:4.17:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:dataparksearch:dataparksearch:4.18:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:dataparksearch:dataparksearch:4.19:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:dataparksearch:dataparksearch:4.20:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:dataparksearch:dataparksearch:4.21:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:dataparksearch:dataparksearch:4.22:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:dataparksearch:dataparksearch:4.23:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:dataparksearch:dataparksearch:4.24:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:dataparksearch:dataparksearch:4.25:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:dataparksearch:dataparksearch:4.26:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:dataparksearch:dataparksearch:4.27:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:dataparksearch:dataparksearch:4.28:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:dataparksearch:dataparksearch:4.29:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:dataparksearch:dataparksearch:4.30:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:dataparksearch:dataparksearch:4.31:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:dataparksearch:dataparksearch:4.32:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:dataparksearch:dataparksearch:4.33:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:dataparksearch:dataparksearch:4.34:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:dataparksearch:dataparksearch:4.35:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:dataparksearch:dataparksearch:4.36:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-13T11:06Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0650",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "cpaint",
            "product" : {
              "product_data" : [ {
                "product_name" : "cpaint",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.01",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3_sp",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3_sp1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "pre1.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://cpaint.booleansystems.com/forums/viewtopic.php?t=98",
          "name" : "http://cpaint.booleansystems.com/forums/viewtopic.php?t=98",
          "refsource" : "CONFIRM",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://secunia.com/advisories/18765",
          "name" : "18765",
          "refsource" : "SECUNIA",
          "tags" : [ "Exploit", "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1015608",
          "name" : "1015608",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.gulftech.org/?node=research&article_id=00097-02092006",
          "name" : "http://www.gulftech.org/?node=research&article_id=00097-02092006",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/424663/100/0/threaded",
          "name" : "20060210 CPAINT AJAX Library Cross Site Scripting",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16559",
          "name" : "16559",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0487",
          "name" : "ADV-2006-0487",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24594",
          "name" : "cpaint-response-type-xss(24594)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in cpaint2.inc.php in the CPAINT library before 2.0.3, as used in multiple scripts, allows remote attackers to inject arbitrary web script or HTML via the cpaint_response_type parameter, which is displayed in a resulting error message, as demonstrated using a hex-encoded IFRAME tag."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cpaint:cpaint:1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cpaint:cpaint:1.01:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cpaint:cpaint:1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cpaint:cpaint:1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cpaint:cpaint:1.3_sp:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cpaint:cpaint:1.3_sp1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cpaint:cpaint:2.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cpaint:cpaint:2.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cpaint:cpaint:2.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cpaint:cpaint:pre1.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-13T11:06Z",
    "lastModifiedDate" : "2018-10-19T15:45Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0651",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "vwdev",
            "product" : {
              "product_data" : [ {
                "product_name" : "vwdev",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://securitytracker.com/id?1015594",
          "name" : "1015594",
          "refsource" : "SECTRACK",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.osvdb.org/22991",
          "name" : "22991",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16547",
          "name" : "16547",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24583",
          "name" : "vwdev-uid-sql-injection(24583)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in index.php in vwdev allows remote attackers to execute arbitrary SQL commands via the UID parameter in the definition Page."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:vwdev:vwdev:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-13T11:06Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0652",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "whmcompletesolution",
            "product" : {
              "product_data" : [ {
                "product_name" : "whmcompletesolution",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/16560",
          "name" : "16560",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0484",
          "name" : "ADV-2006-0484",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.whmcs.com/changelog.php",
          "name" : "http://www.whmcs.com/changelog.php",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24597",
          "name" : "whmcs-resellers-insecure-permissions(24597)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "WHMCompleteSolution (WHMCS) before 2.3 assigns incorrect permissions to \"resellers\", which allows remote authenticated users to perform privileged actions or obtain sensitive information.  NOTE: this report is based on a vendor bug report that identified \"incorrect permissions.\"  However, the vendor did not label it a security issue, and there was no statement regarding whether or not the permissions were actually more permissive than intended.  If in fact the permissions were more restrictive than intended, then this would be a functional problem but not a vulnerability."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:whmcompletesolution:whmcompletesolution:2.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:whmcompletesolution:whmcompletesolution:2.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:whmcompletesolution:whmcompletesolution:2.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.5
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-13T11:06Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0653",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "hinton_design",
            "product" : {
              "product_data" : [ {
                "product_name" : "phpht_topsites",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://evuln.com/vulns/59/summary.html",
          "name" : "http://evuln.com/vulns/59/summary.html",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18782",
          "name" : "18782",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/424741/100/0/threaded",
          "name" : "20060211 [eVuln] phpht Topsites Multiple Vulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16562",
          "name" : "16562",
          "refsource" : "BID",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple SQL injection vulnerabilities in Hinton Design phpht Topsites 1.3 allow remote attackers to execute arbitrary SQL commands via multiple vectors including the username parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hinton_design:phpht_topsites:1.3:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-13T11:06Z",
    "lastModifiedDate" : "2018-10-19T15:45Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0654",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "hinton_design",
            "product" : {
              "product_data" : [ {
                "product_name" : "phpht_topsites",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://evuln.com/vulns/59/summary.html",
          "name" : "http://evuln.com/vulns/59/summary.html",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18782",
          "name" : "18782",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/424741/100/0/threaded",
          "name" : "20060211 [eVuln] phpht Topsites Multiple Vulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16562",
          "name" : "16562",
          "refsource" : "BID",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "check.php in Hinton Design phpht Topsites 1.3 does not validate passwords when using cookies, which allows remote attackers to bypass authentication via unspecified cookies."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hinton_design:phpht_topsites:1.3:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-13T11:06Z",
    "lastModifiedDate" : "2018-10-19T15:45Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0655",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "hinton_design",
            "product" : {
              "product_data" : [ {
                "product_name" : "phpht_topsites",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://evuln.com/vulns/59/summary.html",
          "name" : "http://evuln.com/vulns/59/summary.html",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18782",
          "name" : "18782",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/424741/100/0/threaded",
          "name" : "20060211 [eVuln] phpht Topsites Multiple Vulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16562",
          "name" : "16562",
          "refsource" : "BID",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple cross-site scripting (XSS) vulnerabilities in (1) link_edited.php and (2) link_added.php in Hinton Design phpht Topsites 1.3 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hinton_design:phpht_topsites:1.3:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-13T11:06Z",
    "lastModifiedDate" : "2018-10-19T15:45Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0656",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "hp",
            "product" : {
              "product_data" : [ {
                "product_name" : "systems_insight_manager",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18789",
          "name" : "18789",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1015605",
          "name" : "1015605",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16571",
          "name" : "16571",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0497",
          "name" : "ADV-2006-0497",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=c00597967",
          "name" : "SSRT061108",
          "refsource" : "HP",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Directory traversal vulnerability in HP Systems Insight Manager 4.2 through 5.0 SP3 for Windows allows remote attackers to access arbitrary files via unspecified vectors, a different vulnerability than CVE-2005-2006."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hp:systems_insight_manager:4.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hp:systems_insight_manager:4.2:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hp:systems_insight_manager:4.2:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hp:systems_insight_manager:5.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hp:systems_insight_manager:5.0:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hp:systems_insight_manager:5.0:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hp:systems_insight_manager:5.0:sp3:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-13T11:06Z",
    "lastModifiedDate" : "2011-03-08T02:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0657",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "softcomplex",
            "product" : {
              "product_data" : [ {
                "product_name" : "php_event_calendar",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.5",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://evuln.com/vulns/63/summary.html",
          "name" : "http://evuln.com/vulns/63/summary.html",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18792",
          "name" : "18792",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/442",
          "name" : "442",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/23071",
          "name" : "23071",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/23072",
          "name" : "23072",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16588",
          "name" : "16588",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0507",
          "name" : "ADV-2006-0507",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24523",
          "name" : "phpeventcalendar-users-xss(24523)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in Softcomplex PHP Event Calendar 1.5 allows remote authenticated users to inject arbitrary web script or HTML, and corrupt data, via the (1) username and (2) password parameters, which are not sanitized before being written to users.php.  NOTE: while this issue was originally reported as XSS, the primary issue might be direct static code injection with resultant XSS."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:softcomplex:php_event_calendar:1.5:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:S/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 3.5
        },
        "severity" : "LOW",
        "exploitabilityScore" : 6.8,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-13T11:06Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0658",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "fckeditor",
            "product" : {
              "product_data" : [ {
                "product_name" : "fckeditor",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://retrogod.altervista.org/fckeditor_22_xpl.html",
          "name" : "http://retrogod.altervista.org/fckeditor_22_xpl.html",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://secunia.com/advisories/18767",
          "name" : "18767",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/424708",
          "name" : "20060209 runCMS <= 1.3a2 possible remote code execution through the integrated FCKEditor package",
          "refsource" : "BUGTRAQ",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0502",
          "name" : "ADV-2006-0502",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/3702",
          "name" : "3702",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Incomplete blacklist vulnerability in connector.php in FCKeditor 2.0 and 2.2, as used in products such as RunCMS, allows remote attackers to upload and execute arbitrary script files by giving the files specific extensions that are not listed in the Config[DeniedExtensions][File], such as .php.txt."
        }, {
          "lang" : "en",
          "value" : "Per: http://cwe.mitre.org/data/definitions/184.html\r\n'CWE-184: Incomplete Blacklist'"
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:fckeditor:fckeditor:2.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:fckeditor:fckeditor:2.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-13T11:06Z",
    "lastModifiedDate" : "2017-10-11T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0659",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "runcms",
            "product" : {
              "product_data" : [ {
                "product_name" : "runcms",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1a",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-94"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://retrogod.altervista.org/runcms_13a_xpl.html",
          "name" : "http://retrogod.altervista.org/runcms_13a_xpl.html",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://secunia.com/advisories/18800",
          "name" : "18800",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/424708",
          "name" : "20060209 runCMS <= 1.3a2 possible remote code execution through the integrated FCKEditor package",
          "refsource" : "BUGTRAQ",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16578",
          "name" : "16578",
          "refsource" : "BID",
          "tags" : [ "Exploit", "Patch" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0503",
          "name" : "ADV-2006-0503",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple PHP remote file include vulnerabilities in RunCMS 1.2 and earlier, with register_globals and allow_url_fopen enabled, allow remote attackers to execute arbitrary code via the bbPath[path] parameter in (1) class.forumposts.php and (2) forumpollrenderer.php."
        }, {
          "lang" : "en",
          "value" : "Successful exploitation requires that both \"register_globals\" and \"allow_url_fopen\" are enabled."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:runcms:runcms:1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:runcms:runcms:1.1a:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:runcms:runcms:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.2"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-13T11:06Z",
    "lastModifiedDate" : "2011-09-08T04:00Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0660",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "farsinews",
            "product" : {
              "product_data" : [ {
                "product_name" : "farsinews",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.1_beta2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.5",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://forum.farsinewsteam.com/index.php?showtopic=71",
          "name" : "http://forum.farsinewsteam.com/index.php?showtopic=71",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://forum.farsinewsteam.com/index.php?showtopic=76",
          "name" : "http://forum.farsinewsteam.com/index.php?showtopic=76",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18768",
          "name" : "18768",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.hamid.ir/security/farsinews2-5.txt",
          "name" : "http://www.hamid.ir/security/farsinews2-5.txt",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/23020",
          "name" : "23020",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/23021",
          "name" : "23021",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/23022",
          "name" : "23022",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/424720/100/0/threaded",
          "name" : "20060210 FarsiNews 2.5 Multiple Vulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16580",
          "name" : "16580",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0506",
          "name" : "ADV-2006-0506",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24598",
          "name" : "farsinews-showarchives-file-include(24598)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24602",
          "name" : "farsinews-index-directory-traversal(24602)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple directory traversal vulnerabilities in FarsiNews 2.5 and earlier allows remote attackers to (1) read arbitrary files or trigger an error message path disclosure via \"..\"  or invalid names in the archive parameter to index.php, or (2) include arbitrary files via the template parameter to show_archives.php."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:farsinews:farsinews:2.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:farsinews:farsinews:2.1_beta2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:farsinews:farsinews:2.5:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 6.4
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-13T11:06Z",
    "lastModifiedDate" : "2018-10-19T15:45Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0661",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "scriptme",
            "product" : {
              "product_data" : [ {
                "product_name" : "sme_blog_host",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "sme_gb_host",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.21",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://evuln.com/vulns/65/summary.html",
          "name" : "http://evuln.com/vulns/65/summary.html",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18786",
          "name" : "18786",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/447",
          "name" : "447",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16585",
          "name" : "16585",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0504",
          "name" : "ADV-2006-0504",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24543",
          "name" : "sme-bbcode-xss(24543)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in Scriptme SmE GB Host 1.21 and SmE Blog Host allows remote attackers to inject arbitrary web script or HTML via the BBcode url tag."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:scriptme:sme_blog_host:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:scriptme:sme_gb_host:1.21:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-13T11:06Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0662",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "lotus_domino_inotes_client",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.5.4",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/16340",
          "name" : "16340",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/secunia_research/2005-38/advisory/",
          "name" : "http://secunia.com/secunia_research/2005-38/advisory/",
          "refsource" : "MISC",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1015610",
          "name" : "1015610",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/23077",
          "name" : "23077",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16577",
          "name" : "16577",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0499",
          "name" : "ADV-2006-0499",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www-1.ibm.com/support/docview.wss?rs=475&uid=swg21229919",
          "name" : "http://www-1.ibm.com/support/docview.wss?rs=475&uid=swg21229919",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24612",
          "name" : "domino-webaccess-subject-xss(24612)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in Lotus Domino iNotes Client 6.5.4 allows remote attackers to inject arbitrary web script or HTML via email with attached html files, which are directly rendered in the browser."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:lotus_domino_inotes_client:6.5.4:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-13T11:06Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0663",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "lotus_domino_inotes_client",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.5.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/16340",
          "name" : "16340",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/secunia_research/2005-38/advisory/",
          "name" : "http://secunia.com/secunia_research/2005-38/advisory/",
          "refsource" : "MISC",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1015610",
          "name" : "1015610",
          "refsource" : "SECTRACK",
          "tags" : [ "Exploit", "Patch" ]
        }, {
          "url" : "http://www.osvdb.org/23077",
          "name" : "23077",
          "refsource" : "OSVDB",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.osvdb.org/23078",
          "name" : "23078",
          "refsource" : "OSVDB",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.osvdb.org/23079",
          "name" : "23079",
          "refsource" : "OSVDB",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16577",
          "name" : "16577",
          "refsource" : "BID",
          "tags" : [ "Exploit", "Patch" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0499",
          "name" : "ADV-2006-0499",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www-1.ibm.com/support/docview.wss?rs=475&uid=swg21229919",
          "name" : "http://www-1.ibm.com/support/docview.wss?rs=475&uid=swg21229919",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24611",
          "name" : "domino-webaccess-attachment-xss(24611)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24613",
          "name" : "domino-webaccess-javascript-xss(24613)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24614",
          "name" : "domino-webaccess-filename-xss(24614)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple cross-site scripting (XSS) vulnerabilities in Lotus Domino iNotes Client 6.5.4 and 7.0 allow remote attackers to inject arbitrary web script or HTML via (1) an email subject; (2) an encoded javascript URI, as demonstrated using \"java&#13;script:\"; or (3) when the Domino Web Access ActiveX control is not installed, via an email attachment filename."
        }, {
          "lang" : "en",
          "value" : "This vulnerability is addressed in the following product releases:\r\nIBM, Lotus Domino iNotes Client, 6.5.5\r\nIBM, Lotus Domino iNotes Client, 7.0.1"
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:lotus_domino_inotes_client:6.5.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:lotus_domino_inotes_client:7.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2006-02-13T11:06Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0664",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "mantis",
            "product" : {
              "product_data" : [ {
                "product_name" : "mantis",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.17.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.17.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.17.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.17.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.17.4a",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.17.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.18",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.18.0_rc1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.18.0a2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.18.0a3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.18.0a4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.18.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.18.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.18a1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.19.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.19.0_rc1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.19.0a",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.19.0a1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.19.0a2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.19.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.19.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.19.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.19.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.0_rc1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.0_rc2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.0_rc3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.0_rc4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.0a1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.0a2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.0a3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/21400",
          "name" : "21400",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2006/dsa-1133",
          "name" : "DSA-1133",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16561",
          "name" : "16561",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0485",
          "name" : "ADV-2006-0485",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24585",
          "name" : "mantis-configdefaultsinc-xss(24585)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in config_defaults_inc.php in Mantis before 1.0 allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.  An original vendor bug report is referenced, but not accessible to the general public."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.17.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.17.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.17.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.17.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.17.4a:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.17.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.18:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.18.0_rc1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.18.0a2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.18.0a3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.18.0a4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.18.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.18.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.18a1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.19.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.19.0_rc1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.19.0a:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.19.0a1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.19.0a2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.19.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.19.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.19.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.19.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:1.0.0_rc1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:1.0.0_rc2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:1.0.0_rc3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:1.0.0_rc4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:1.0.0a1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:1.0.0a2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:1.0.0a3:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-13T11:06Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0665",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "mantis",
            "product" : {
              "product_data" : [ {
                "product_name" : "mantis",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.17.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.17.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.17.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.17.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.17.4a",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.17.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.18",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.18.0_rc1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.18.0a2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.18.0a3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.18.0a4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.18.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.18.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.18a1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.19.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.19.0_rc1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.19.0a",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.19.0a1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.19.0a2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.19.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.19.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.19.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.19.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.0_rc1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.0_rc2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.0_rc3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.0_rc4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.0a1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.0a2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.0a3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/21400",
          "name" : "21400",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2006/dsa-1133",
          "name" : "DSA-1133",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16561",
          "name" : "16561",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0485",
          "name" : "ADV-2006-0485",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in (1) query_store.php and (2) manage_proj_create.php in Mantis before 1.0.0 has unknown impact and attack vectors.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.  An original vendor bug report is referenced, but not accessible to the general public."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.17.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.17.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.17.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.17.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.17.4a:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.17.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.18:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.18.0_rc1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.18.0a2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.18.0a3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.18.0a4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.18.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.18.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.18a1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.19.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.19.0_rc1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.19.0a:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.19.0a1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.19.0a2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.19.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.19.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.19.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.19.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:1.0.0_rc1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:1.0.0_rc2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:1.0.0_rc3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:1.0.0_rc4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:1.0.0a1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:1.0.0a2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:1.0.0a3:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-13T11:06Z",
    "lastModifiedDate" : "2011-03-08T02:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0666",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "aix",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.3_l",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18795",
          "name" : "18795",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/23127",
          "name" : "23127",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16624",
          "name" : "16624",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0573",
          "name" : "ADV-2006-0573",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www-1.ibm.com/support/search.wss?rs=0&q=IY79595&apar=only",
          "name" : "IY79595",
          "refsource" : "AIXAPAR",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24711",
          "name" : "aix-kernel-dos(24711)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the (1) unix_mp and (2) unix_64 kernels in IBM AIX 5.3 VRMF 5.3.0.30 through 5.3.0.33 allows local users to cause a denial of service (system crash) via unknown vectors related to EMULATE_VMX."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:ibm:aix:5.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:ibm:aix:5.3_l:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:N/I:N/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 4.9
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 3.9,
        "impactScore" : 6.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-15T11:06Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0667",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "aix",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://securitytracker.com/id?1015622",
          "name" : "1015622",
          "refsource" : "SECTRACK",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2005/2096",
          "name" : "ADV-2005-2096",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www-1.ibm.com/support/docview.wss?uid=isg1IY77624",
          "name" : "IY77624",
          "refsource" : "AIXAPAR",
          "tags" : [ ]
        }, {
          "url" : "http://www-1.ibm.com/support/docview.wss?uid=isg1IY77638",
          "name" : "IY77638",
          "refsource" : "AIXAPAR",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "lscfg in IBM AIX 5.2 and 5.3 allows local users to modify arbitrary files via a symlink attack."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:ibm:aix:5.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:ibm:aix:5.3:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 4.6
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 3.9,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-03-10T01:02Z",
    "lastModifiedDate" : "2011-03-08T02:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0668",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "pwsphp",
            "product" : {
              "product_data" : [ {
                "product_name" : "pwsphp",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.2.3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/19023",
          "name" : "19023",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16567",
          "name" : "16567",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16567/exploit",
          "name" : "http://www.securityfocus.com/bid/16567/exploit",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in index.php in PwsPHP 1.2.3 allows remote attackers to execute arbitrary SQL commands via the id parameter, possibly in message.php in the espace_membre module.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pwsphp:pwsphp:1.2.3:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-13T22:02Z",
    "lastModifiedDate" : "2008-09-05T20:59Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0669",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "gasoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "gas_forum_light",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://securitytracker.com/id?1015600",
          "name" : "1015600",
          "refsource" : "SECTRACK",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.attrition.org/pipermail/vim/2006-February/000561.html",
          "name" : "20060220 vendor dispute for CVE-2006-0669",
          "refsource" : "VIM",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/23509",
          "name" : "23509",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16563",
          "name" : "16563",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24616",
          "name" : "gasforumlight-archive-sql-injection(24616)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "** DISPUTED **  Multiple SQL injection vulnerabilities in archive.asp in GA's Forum Light allow remote attackers to execute arbitrary SQL commands via the (1) Forum and (2) pages parameter.  NOTE: SecurityTracker says that the vendor has disputed this issue, saying that GA Forum Light does not use an SQL database.  SecurityTracker's research indicates that the original problem could be due to a vbscript parsing error based on invalid arguments."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:gasoft:gas_forum_light:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-13T22:02Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0670",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "bluez_project",
            "product" : {
              "product_data" : [ {
                "product_name" : "hcidump",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.29",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://marc.info/?l=full-disclosure&m=113924625825488&w=2",
          "name" : "20060206 [ Secuobs - Advisory ] Bluetooth : DoS on hcidump",
          "refsource" : "FULLDISC",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18741",
          "name" : "18741",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18971",
          "name" : "18971",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/19122",
          "name" : "19122",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/465",
          "name" : "465",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2006/dsa-990",
          "name" : "DSA-990",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDKSA-2006:041",
          "name" : "MDKSA-2006:041",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/23056",
          "name" : "23056",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.secuobs.com/news/05022006-bluetooth9.shtml#english",
          "name" : "http://www.secuobs.com/news/05022006-bluetooth9.shtml#english",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/424133/100/0/threaded",
          "name" : "20060206 [ Secuobs - Advisory ] Bluetooth : DoS on hcidump 1.29 + PoC",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/usn-256-1",
          "name" : "USN-256-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0479",
          "name" : "ADV-2006-0479",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24533",
          "name" : "hcidump-bluetooth-dos(24533)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Buffer overflow in l2cap.c in hcidump 1.29 allows remote attackers to cause a denial of service (crash) through a wireless Bluetooth connection via a malformed Logical Link Control and Adaptation Protocol (L2CAP) packet."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bluez_project:hcidump:1.29:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-13T22:02Z",
    "lastModifiedDate" : "2018-10-19T15:45Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0671",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "sony_ericsson",
            "product" : {
              "product_data" : [ {
                "product_name" : "k600i",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "t68i",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "v600i",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "w800i",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://marc.info/?l=bugtraq&m=113926179907655&w=2",
          "name" : "20060206 [ Secuobs - Advisory ] Bluetooth : DoS on Sony/Ericsson cell phones",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://marc.info/?l=full-disclosure&m=113924661724270&w=2",
          "name" : "20060206 [Full-disclosure] [ Secuobs - Advisory ] Bluetooth : DoS on",
          "refsource" : "FULLDISC",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18747",
          "name" : "18747",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.secuobs.com/news/05022006-bluetooth7.shtml#english",
          "name" : "http://www.secuobs.com/news/05022006-bluetooth7.shtml#english",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16512",
          "name" : "16512",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0478",
          "name" : "ADV-2006-0478",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24534",
          "name" : "sony-bluetooth-dos(24534)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Buffer overflow in Sony Ericsson K600i, V600i, W800i, and T68i cell phone allows remote attackers to cause a denial of service (reboot or shutdown) through a wireless Bluetooth connection via a malformed Logical Link Control and Adaptation Protocol (L2CAP) packet whose length field is less than the actual length of the packet."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:sony_ericsson:k600i:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:sony_ericsson:t68i:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:sony_ericsson:v600i:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:sony_ericsson:w800i:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.8
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-13T22:02Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0672",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "hp",
            "product" : {
              "product_data" : [ {
                "product_name" : "psc_1210_all-in-one",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.0.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://h10025.www1.hp.com/ewfrf/wc/softwareDownloadIndex?dlc=en&lc=en&os=228%20&product=90764&lang=en&cc=us&softwareitem=oj-37641-1",
          "name" : "http://h10025.www1.hp.com/ewfrf/wc/softwareDownloadIndex?dlc=en&lc=en&os=228%20&product=90764&lang=en&cc=us&softwareitem=oj-37641-1",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://secunia.com/advisories/18770",
          "name" : "18770",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16583",
          "name" : "16583",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0498",
          "name" : "ADV-2006-0498",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in HP PSC 1210 All-in-One Drivers before 1.0.06 has unknown impact and attack vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:hp:psc_1210_all-in-one:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:hp:psc_1210_all-in-one:1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:hp:psc_1210_all-in-one:1.0.0.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-13T22:02Z",
    "lastModifiedDate" : "2011-03-07T05:00Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0673",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "reamday_enterprises",
            "product" : {
              "product_data" : [ {
                "product_name" : "magic_calendar_lite",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.02",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://evuln.com/vulns/71/summary.html",
          "name" : "http://evuln.com/vulns/71/summary.html",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18855",
          "name" : "18855",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/459",
          "name" : "459",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1015650",
          "name" : "1015650",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/425491/100/0/threaded",
          "name" : "20060220 [eVuln] Magic Calendar Lite Authentication Bypass",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16646",
          "name" : "16646",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16734",
          "name" : "16734",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0525",
          "name" : "ADV-2006-0525",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24588",
          "name" : "magiccalendar-index-sql-injection(24588)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple SQL injection vulnerabilities in cms/index.php in Magic Calendar Lite 1.02, with magic_quotes_gpc disabled, allow remote attackers to execute arbitrary SQL commands via the (1) $total_login and (2) $total_password parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:reamday_enterprises:magic_calendar_lite:1.02:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-13T22:02Z",
    "lastModifiedDate" : "2018-10-19T15:45Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0674",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "aix",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.2.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.2_l",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.3_l",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18773",
          "name" : "18773",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16584",
          "name" : "16584",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0531",
          "name" : "ADV-2006-0531",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www-1.ibm.com/support/docview.wss?rs=0&q1=IY81424&uid=isg1IY81424&loc=en_US&cs=utf-8&cc=us&lang=en",
          "name" : "IY81424",
          "refsource" : "AIXAPAR",
          "tags" : [ ]
        }, {
          "url" : "http://www-1.ibm.com/support/docview.wss?uid=isg1IY81476",
          "name" : "IY81476",
          "refsource" : "AIXAPAR",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24628",
          "name" : "aix-arp-iftype-bo(24628)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Buffer overflow in the arp command of IBM AIX 5.3 L, 5.3, 5.2.2, 5.2 L, and 5.2 allows local users to cause a denial of service (crash) via a long iftype argument."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:ibm:aix:5.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:ibm:aix:5.2.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:ibm:aix:5.2_l:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:ibm:aix:5.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:ibm:aix:5.3_l:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 4.6
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 3.9,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-13T22:02Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0675",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "glen_campbell",
            "product" : {
              "product_data" : [ {
                "product_name" : "siteframe",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.0.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://kiki91.altervista.org/exploit/siteframe5.0.1a_xss.txt",
          "name" : "http://kiki91.altervista.org/exploit/siteframe5.0.1a_xss.txt",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18804",
          "name" : "18804",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://siteframe.org/p/xss_vulnerability_in_siteframe_501",
          "name" : "http://siteframe.org/p/xss_vulnerability_in_siteframe_501",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/424844/100/0/threaded",
          "name" : "20060212 Siteframe Beaumont 5.0.1a <== Cross-Site Scripting Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16596",
          "name" : "16596",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0533",
          "name" : "ADV-2006-0533",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24649",
          "name" : "siteframe-search-request-xss(24649)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in search.php in Siteframe 5.0.1 allows remote attackers to inject arbitrary web script or HTML via the q parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:glen_campbell:siteframe:5.0.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-13T22:02Z",
    "lastModifiedDate" : "2018-10-19T15:45Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0676",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "francisco_burzi",
            "product" : {
              "product_data" : [ {
                "product_name" : "php-nuke",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.5_beta1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.5_final",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.5_rc1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.5_rc2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.5_rc3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.9",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18820",
          "name" : "18820",
          "refsource" : "SECUNIA",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/425",
          "name" : "425",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/424956/100/0/threaded",
          "name" : "20060214 [waraxe-2006-SA#044] - XSS in phpNuke 7.8 and older versions",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16608",
          "name" : "16608",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0542",
          "name" : "ADV-2006-0542",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.waraxe.us/advisory-44.html",
          "name" : "http://www.waraxe.us/advisory-44.html",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24650",
          "name" : "phpnuke-header-xss(24650)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in header.php in PHP-Nuke 6.0 to 7.8 allows remote attackers to inject arbitrary web script or HTML via the pagetitle parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:francisco_burzi:php-nuke:6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:francisco_burzi:php-nuke:6.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:francisco_burzi:php-nuke:6.5_beta1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:francisco_burzi:php-nuke:6.5_final:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:francisco_burzi:php-nuke:6.5_rc1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:francisco_burzi:php-nuke:6.5_rc2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:francisco_burzi:php-nuke:6.5_rc3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:francisco_burzi:php-nuke:6.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:francisco_burzi:php-nuke:6.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:francisco_burzi:php-nuke:6.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:francisco_burzi:php-nuke:7.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:francisco_burzi:php-nuke:7.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:francisco_burzi:php-nuke:7.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:francisco_burzi:php-nuke:7.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:francisco_burzi:php-nuke:7.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:francisco_burzi:php-nuke:7.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:francisco_burzi:php-nuke:7.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:francisco_burzi:php-nuke:7.9:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-13T22:02Z",
    "lastModifiedDate" : "2018-10-19T15:45Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0677",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "kth",
            "product" : {
              "product_data" : [ {
                "product_name" : "heimdal",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.6.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.6.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.6.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.6.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.6.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.7.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.7.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.7.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.7.1.3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18894",
          "name" : "18894",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18961",
          "name" : "18961",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/19005",
          "name" : "19005",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/449",
          "name" : "449",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2006/dsa-977",
          "name" : "DSA-977",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/23244",
          "name" : "23244",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/426043/100/0/threaded",
          "name" : "SUSE-SA:2006:011",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16676",
          "name" : "16676",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.stacken.kth.se/lists/heimdal-discuss/2006-02/msg00028.html",
          "name" : "[heimdal-discuss] 20060206 Heimdal 0.7.2 and 0.6.6",
          "refsource" : "MLIST",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.ubuntu.com/usn/usn-253-1",
          "name" : "USN-253-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0456",
          "name" : "ADV-2006-0456",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0628",
          "name" : "ADV-2006-0628",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0653",
          "name" : "ADV-2006-0653",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24763",
          "name" : "heimdal-telnetd-dos(24763)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "telnetd in Heimdal 0.6.x before 0.6.6 and 0.7.x before 0.7.2 allows remote unauthenticated attackers to cause a denial of service (server crash) via unknown vectors that trigger a null dereference."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:kth:heimdal:0.6.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:kth:heimdal:0.6.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:kth:heimdal:0.6.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:kth:heimdal:0.6.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:kth:heimdal:0.6.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:kth:heimdal:0.7.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:kth:heimdal:0.7.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:kth:heimdal:0.7.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:kth:heimdal:0.7.1.3:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.8
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-14T11:06Z",
    "lastModifiedDate" : "2018-10-19T15:45Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0678",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "postgresql",
            "product" : {
              "product_data" : [ {
                "product_name" : "postgresql",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.3.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.3.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.3.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.3.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.3.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.3.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.3.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.3.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.3.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.3.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.3.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.3.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.3.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.4.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.4.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.4.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.4.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.4.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.4.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.4.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.4.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.4.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.4.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.4.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.1.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18890",
          "name" : "18890",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/19015",
          "name" : "19015",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/19035",
          "name" : "19035",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/498",
          "name" : "498",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.openpkg.org/security/OpenPKG-SA-2006.004-postgresql.html",
          "name" : "OpenPKG-SA-2006.004",
          "refsource" : "OPENPKG",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.postgresql.org/docs/8.1/static/release.html#RELEASE-8-1-3",
          "name" : "http://www.postgresql.org/docs/8.1/static/release.html#RELEASE-8-1-3",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/425037/100/0/threaded",
          "name" : "20060215 PostgreSQL security releases 8.1.3, 8.0.7, 7.4.12, 7.3.14",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16650",
          "name" : "16650",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.trustix.org/errata/2006/0008",
          "name" : "2006-0008",
          "refsource" : "TRUSTIX",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/usn-258-1",
          "name" : "USN-258-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0605",
          "name" : "ADV-2006-0605",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24719",
          "name" : "postgresql-setsessionauth-dos(24719)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "PostgreSQL 7.3.x before 7.3.14, 7.4.x before 7.4.12, 8.0.x before 8.0.7, and 8.1.x before 8.1.3, when compiled with Asserts enabled, allows local users to cause a denial of service (server crash) via a crafted SET SESSION AUTHORIZATION command, a different vulnerability than CVE-2006-0553."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:7.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:7.3.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:7.3.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:7.3.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:7.3.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:7.3.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:7.3.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:7.3.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:7.3.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:7.3.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:7.3.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:7.3.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:7.3.12:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:7.3.13:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:7.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:7.4.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:7.4.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:7.4.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:7.4.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:7.4.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:7.4.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:7.4.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:7.4.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:7.4.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:7.4.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:7.4.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:8.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:8.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:8.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:8.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:8.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:8.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:8.0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:8.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:8.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:8.1.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:M/Au:S/C:N/I:N/A:P",
          "accessVector" : "LOCAL",
          "accessComplexity" : "MEDIUM",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 1.5
        },
        "severity" : "LOW",
        "exploitabilityScore" : 2.7,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-14T19:06Z",
    "lastModifiedDate" : "2018-10-19T15:45Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0679",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "francisco_burzi",
            "product" : {
              "product_data" : [ {
                "product_name" : "php-nuke_ev",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.8",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://archives.neohapsis.com/archives/fulldisclosure/2006-02/0358.html",
          "name" : "20060216 Critical SQL Injection PHPNuke <= 7.8 - Your_Account module",
          "refsource" : "FULLDISC",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18931",
          "name" : "18931",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/achievement_securityalert/32",
          "name" : "20060216 Critical SQL Injection PHPNuke <= 7.8 - Your_Account module",
          "refsource" : "SREASONRES",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/440",
          "name" : "440",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/23259",
          "name" : "23259",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/425173/100/0/threaded",
          "name" : "20060216 Critical SQL Injection PHPNuke <= 7.8 - Your_Account module",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16691",
          "name" : "16691",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0636",
          "name" : "ADV-2006-0636",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24769",
          "name" : "phpnuke-youraccount-sql-injection(24769)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in index.php in the Your_Account module in PHP-Nuke 7.8 and earlier allows remote attackers to execute arbitrary SQL commands via the username variable (Nickname field)."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:francisco_burzi:php-nuke_ev:7.8:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-16T20:06Z",
    "lastModifiedDate" : "2018-10-19T15:45Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0680",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "plain_black",
            "product" : {
              "product_data" : [ {
                "product_name" : "webgui",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.2.0_beta",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.2.1_beta",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.2.2_beta",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.2.3_beta",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.2.4_beta",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.2.5_beta",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.2.6_gamma",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.2.7_gamma",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.2.8_gamma",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.2.9_gamma",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.2.10_gamma",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.2.11_gamma",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.3.0_beta",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.4.0_beta",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.5.0_beta",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.5.1_beta",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.5.2_beta",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.5.3_beta",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.5.4_gamma",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.5.5_gamma",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.5.6_gamma",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.6.0_beta",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.6.1_beta",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.6.2_gamma",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.6.3_gamma",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.6.4_gamma",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.6.5_gamma",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.7.0_beta",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.7.1_beta",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.7.2_beta",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.7.3_gamma",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.7.4_gamma",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.7.5_gamma",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.7.6_gamma",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.7.7_gamma",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.7.8_gamma",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.8.1_beta",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.8.2_beta",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.8.3_gamma",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.8.4_gamma",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.8.5_gamma",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18819",
          "name" : "18819",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.plainblack.com/getwebgui/advisories/webgui-6.8.6-gamma-released",
          "name" : "http://www.plainblack.com/getwebgui/advisories/webgui-6.8.6-gamma-released",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16612",
          "name" : "16612",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0541",
          "name" : "ADV-2006-0541",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24695",
          "name" : "webgui-anonymous-bypass-security(24695)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in WebGUI before 6.8.6-gamma allows remote attackers to create an account, when anonymous registration is disabled, via a certain URL."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:plain_black:webgui:6.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:plain_black:webgui:6.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:plain_black:webgui:6.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:plain_black:webgui:6.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:plain_black:webgui:6.1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:plain_black:webgui:6.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:plain_black:webgui:6.2.0_beta:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:plain_black:webgui:6.2.1_beta:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:plain_black:webgui:6.2.2_beta:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:plain_black:webgui:6.2.3_beta:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:plain_black:webgui:6.2.4_beta:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:plain_black:webgui:6.2.5_beta:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:plain_black:webgui:6.2.6_gamma:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:plain_black:webgui:6.2.7_gamma:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:plain_black:webgui:6.2.8_gamma:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:plain_black:webgui:6.2.9_gamma:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:plain_black:webgui:6.2.10_gamma:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:plain_black:webgui:6.2.11_gamma:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:plain_black:webgui:6.3.0_beta:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:plain_black:webgui:6.4.0_beta:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:plain_black:webgui:6.5.0_beta:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:plain_black:webgui:6.5.1_beta:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:plain_black:webgui:6.5.2_beta:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:plain_black:webgui:6.5.3_beta:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:plain_black:webgui:6.5.4_gamma:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:plain_black:webgui:6.5.5_gamma:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:plain_black:webgui:6.5.6_gamma:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:plain_black:webgui:6.6.0_beta:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:plain_black:webgui:6.6.1_beta:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:plain_black:webgui:6.6.2_gamma:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:plain_black:webgui:6.6.3_gamma:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:plain_black:webgui:6.6.4_gamma:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:plain_black:webgui:6.6.5_gamma:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:plain_black:webgui:6.7.0_beta:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:plain_black:webgui:6.7.1_beta:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:plain_black:webgui:6.7.2_beta:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:plain_black:webgui:6.7.3_gamma:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:plain_black:webgui:6.7.4_gamma:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:plain_black:webgui:6.7.5_gamma:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:plain_black:webgui:6.7.6_gamma:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:plain_black:webgui:6.7.7_gamma:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:plain_black:webgui:6.7.8_gamma:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:plain_black:webgui:6.8.1_beta:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:plain_black:webgui:6.8.2_beta:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:plain_black:webgui:6.8.3_gamma:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:plain_black:webgui:6.8.4_gamma:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:plain_black:webgui:6.8.5_gamma:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-15T00:02Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0681",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "power_daemon",
            "product" : {
              "product_data" : [ {
                "product_name" : "power_daemon",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://gotfault.net/research/advisory/gadv-powerd.txt",
          "name" : "http://gotfault.net/research/advisory/gadv-powerd.txt",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18841",
          "name" : "18841",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16582",
          "name" : "16582",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0545",
          "name" : "ADV-2006-0545",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24713",
          "name" : "powerdaemon-syslog-format-string(24713)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Format string vulnerability in powerd.c in Power Daemon (powerd) 2.0.2 and earlier allows remote attackers to execute arbitrary code via format string specifiers in the WHATIDO variable."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:power_daemon:power_daemon:2.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:power_daemon:power_daemon:2.0.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:power_daemon:power_daemon:2.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:power_daemon:power_daemon:2.0.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:power_daemon:power_daemon:2.0.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-15T00:02Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0682",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "e107",
            "product" : {
              "product_data" : [ {
                "product_name" : "e107",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.7.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.547_beta",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.548_beta",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.549_beta",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.551_beta",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.552_beta",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.553_beta",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.554_beta",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.555_beta",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.600",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.601",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.602",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.603",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.604",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.605",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.606",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.607",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.608",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.609",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.610",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.611",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.612",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.613",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.614",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.615",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.615a",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.616",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.617",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.6171",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.6172",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.6173",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.6174",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.6175",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.3_beta",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.3_beta2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.04",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.4_beta1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.4_beta3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.4_beta4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.4_beta5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.4_beta6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.05",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://e107.org/comment.php?comment.news.776",
          "name" : "http://e107.org/comment.php?comment.news.776",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18816",
          "name" : "18816",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16614",
          "name" : "16614",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0540",
          "name" : "ADV-2006-0540",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24625",
          "name" : "e107-bbcode-xss(24625)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple cross-site scripting (XSS) vulnerabilities in bbcodes system in e107 before 0.7.2 allow remote attackers to inject arbitrary web script or HTML via unknown attack vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:e107:e107:0.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:e107:e107:0.7.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:e107:e107:0.547_beta:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:e107:e107:0.548_beta:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:e107:e107:0.549_beta:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:e107:e107:0.551_beta:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:e107:e107:0.552_beta:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:e107:e107:0.553_beta:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:e107:e107:0.554_beta:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:e107:e107:0.555_beta:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:e107:e107:0.600:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:e107:e107:0.601:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:e107:e107:0.602:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:e107:e107:0.603:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:e107:e107:0.604:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:e107:e107:0.605:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:e107:e107:0.606:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:e107:e107:0.607:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:e107:e107:0.608:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:e107:e107:0.609:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:e107:e107:0.610:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:e107:e107:0.611:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:e107:e107:0.612:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:e107:e107:0.613:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:e107:e107:0.614:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:e107:e107:0.615:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:e107:e107:0.615a:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:e107:e107:0.616:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:e107:e107:0.617:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:e107:e107:0.6171:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:e107:e107:0.6172:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:e107:e107:0.6173:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:e107:e107:0.6174:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:e107:e107:0.6175:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:e107:e107:5.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:e107:e107:5.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:e107:e107:5.3_beta:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:e107:e107:5.3_beta2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:e107:e107:5.04:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:e107:e107:5.4_beta1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:e107:e107:5.4_beta3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:e107:e107:5.4_beta4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:e107:e107:5.4_beta5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:e107:e107:5.4_beta6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:e107:e107:5.05:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-15T00:02Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0683",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "virtual_hosting_control_system",
            "product" : {
              "product_data" : [ {
                "product_name" : "virtual_hosting_control_system",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.4.6.2",
                    "version_affected" : "<="
                  }, {
                    "version_value" : "2.4.7.1_patch_v.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18799",
          "name" : "18799",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.rs-labs.com/adv/RS-Labs-Advisory-2006-1.txt",
          "name" : "http://www.rs-labs.com/adv/RS-Labs-Advisory-2006-1.txt",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/424816/100/0/threaded",
          "name" : "20060211 RS-2006-1: Multiple flaws in VHCS 2.x",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16600",
          "name" : "16600",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0534",
          "name" : "ADV-2006-0534",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24664",
          "name" : "vhcs-admin-xss(24664)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in Virtual Hosting Control System (VHCS) 2.4.7.1 with v.1 patch and earlier allows remote attackers to inject arbitrary web script or HTML via the username, which is recorded in a log file but not properly handled when the administrator uses the admin log utility to read the log file."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:virtual_hosting_control_system:virtual_hosting_control_system:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "2.4.6.2"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:virtual_hosting_control_system:virtual_hosting_control_system:2.4.7.1_patch_v.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-15T00:02Z",
    "lastModifiedDate" : "2018-10-19T15:45Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0684",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "virtual_hosting_control_system",
            "product" : {
              "product_data" : [ {
                "product_name" : "virtual_hosting_control_system",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.4.7.1",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18799",
          "name" : "18799",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.rs-labs.com/adv/RS-Labs-Advisory-2006-1.txt",
          "name" : "http://www.rs-labs.com/adv/RS-Labs-Advisory-2006-1.txt",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/424816/100/0/threaded",
          "name" : "20060211 RS-2006-1: Multiple flaws in VHCS 2.x",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16600",
          "name" : "16600",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0534",
          "name" : "ADV-2006-0534",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24665",
          "name" : "vhcs-change-password-weakness(24665)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "change_password.php in Virtual Hosting Control System (VHCS) 2.4.7.1 and earlier does not verify the old password when a user changes the password, which may allow remote attackers to gain unauthorized access."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:virtual_hosting_control_system:virtual_hosting_control_system:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "2.4.7.1"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-15T00:02Z",
    "lastModifiedDate" : "2018-10-19T15:45Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0685",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "virtual_hosting_control_system",
            "product" : {
              "product_data" : [ {
                "product_name" : "virtual_hosting_control_system",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.4.7.1",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18799",
          "name" : "18799",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.rs-labs.com/adv/RS-Labs-Advisory-2006-1.txt",
          "name" : "http://www.rs-labs.com/adv/RS-Labs-Advisory-2006-1.txt",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/424816/100/0/threaded",
          "name" : "20060211 RS-2006-1: Multiple flaws in VHCS 2.x",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16600",
          "name" : "16600",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0534",
          "name" : "ADV-2006-0534",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24666",
          "name" : "vhcs-checklogin-auth-bypass(24666)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The check_login function in login.php in Virtual Hosting Control System (VHCS) 2.4.7.1 and earlier does not exit when authentication fails, which allows remote attackers to gain unauthorized access."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:virtual_hosting_control_system:virtual_hosting_control_system:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "2.4.7.1"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-15T00:02Z",
    "lastModifiedDate" : "2018-10-19T15:45Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0686",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "virtual_hosting_control_system",
            "product" : {
              "product_data" : [ {
                "product_name" : "virtual_hosting_control_system",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.4.7.1",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18799",
          "name" : "18799",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/430",
          "name" : "430",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.rs-labs.com/adv/RS-Labs-Advisory-2006-1.txt",
          "name" : "http://www.rs-labs.com/adv/RS-Labs-Advisory-2006-1.txt",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/424816/100/0/threaded",
          "name" : "20060211 RS-2006-1: Multiple flaws in VHCS 2.x",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16600",
          "name" : "16600",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0534",
          "name" : "ADV-2006-0534",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24667",
          "name" : "vhcs-adduser-privilege-escalation(24667)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "add_user.php in Virtual Hosting Control System (VHCS) 2.4.7.1 and earlier does not check user privileges when adding a new administrative user, which allows remote attackers to gain unauthorized access."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:virtual_hosting_control_system:virtual_hosting_control_system:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "2.4.7.1"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-15T00:02Z",
    "lastModifiedDate" : "2018-10-19T15:45Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0687",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "docmgr",
            "product" : {
              "product_data" : [ {
                "product_name" : "docmgr",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.54.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://retrogod.altervista.org/docmgr_0542_incl_xpl.html",
          "name" : "http://retrogod.altervista.org/docmgr_0542_incl_xpl.html",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://secunia.com/advisories/18803",
          "name" : "18803",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/428",
          "name" : "428",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/424818/100/0/threaded",
          "name" : "20060212 DocMGR <= 0.54.2 arbitrary remote inclusion",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16601",
          "name" : "16601",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0544",
          "name" : "ADV-2006-0544",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24694",
          "name" : "docmgr-process-file-include(24694)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "process.php in DocMGR 0.54.2 does not initialize the $siteModInfo variable when a direct request is made, which allows remote attackers to include arbitrary local files or possibly remote files via a modified includeModule and siteModInfo variable."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:docmgr:docmgr:0.54.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-15T00:02Z",
    "lastModifiedDate" : "2018-10-19T15:45Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0688",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "nicecoder",
            "product" : {
              "product_data" : [ {
                "product_name" : "indexu",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://echo.or.id/adv/adv26-K-159-2006.txt",
          "name" : "http://echo.or.id/adv/adv26-K-159-2006.txt",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://echo.or.id/adv/adv27-K-159-2006.txt",
          "name" : "http://echo.or.id/adv/adv27-K-159-2006.txt",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18752",
          "name" : "18752",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1015607",
          "name" : "1015607",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/22989",
          "name" : "22989",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/424549/100/0/threaded",
          "name" : "20060209 [ECHO_ADV_27$2006] Indexu <= 5.0.1 Remote File Inclusion",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16565",
          "name" : "16565",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0494",
          "name" : "ADV-2006-0494",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24603",
          "name" : "indexu-application-file-include(24603)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "PHP remote file include vulnerability in application.php in nicecoder.com indexu 5.0.0 and 5.0.1 allows remote attackers to execute arbitrary PHP code via a URL in the base_path parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:nicecoder:indexu:5.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:nicecoder:indexu:5.0.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-15T11:06Z",
    "lastModifiedDate" : "2018-10-19T15:45Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0689",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "scheduling_management.com",
            "product" : {
              "product_data" : [ {
                "product_name" : "time_tracking_software",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18854",
          "name" : "18854",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.evuln.com/vulns/69/summary.html",
          "name" : "http://www.evuln.com/vulns/69/summary.html",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/425505/100/0/threaded",
          "name" : "20060219 [eVuln] Time Tracking Software Multiple Vulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16630",
          "name" : "16630",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0524",
          "name" : "ADV-2006-0524",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24572",
          "name" : "timetracking-registration-xss(24572)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in the Registration Form in TTS Time Tracking Software 3.0 allows remote attackers to inject arbitrary web script or HTML via the UserName parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:scheduling_management.com:time_tracking_software:3.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-15T11:06Z",
    "lastModifiedDate" : "2018-10-19T15:45Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0690",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "scheduling_management.com",
            "product" : {
              "product_data" : [ {
                "product_name" : "time_tracking_software",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18854",
          "name" : "18854",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.evuln.com/vulns/69/summary.html",
          "name" : "http://www.evuln.com/vulns/69/summary.html",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/425505/100/0/threaded",
          "name" : "20060219 [eVuln] Time Tracking Software Multiple Vulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16630",
          "name" : "16630",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0524",
          "name" : "ADV-2006-0524",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24571",
          "name" : "timetracking-multiple-sql-injection(24571)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple SQL injection vulnerabilities in TTS Time Tracking Software 3.0 allow remote attackers to execute arbitrary SQL commands via unspecified vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:scheduling_management.com:time_tracking_software:3.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-15T11:06Z",
    "lastModifiedDate" : "2018-10-19T15:45Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0691",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "scheduling_management.com",
            "product" : {
              "product_data" : [ {
                "product_name" : "time_tracking_software",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18854",
          "name" : "18854",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.evuln.com/vulns/69/summary.html",
          "name" : "http://www.evuln.com/vulns/69/summary.html",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/425505/100/0/threaded",
          "name" : "20060219 [eVuln] Time Tracking Software Multiple Vulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16630",
          "name" : "16630",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16731",
          "name" : "16731",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0524",
          "name" : "ADV-2006-0524",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24570",
          "name" : "timetracking-edituser-auth-bypass(24570)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "edituser.php in TTS Time Tracking Software 3.0 does not verify that the name and password are correct, which allows remote attackers to overwrite arbitrary data belonging to any account."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:scheduling_management.com:time_tracking_software:3.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-15T11:06Z",
    "lastModifiedDate" : "2018-10-19T15:45Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0692",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "carey_briggs",
            "product" : {
              "product_data" : [ {
                "product_name" : "php_mysql_timesheet",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18822",
          "name" : "18822",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/451",
          "name" : "451",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.evuln.com/vulns/67/summary.html",
          "name" : "http://www.evuln.com/vulns/67/summary.html",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/425316/100/0/threaded",
          "name" : "20060217 [eVuln] PHP/MYSQL Timesheet Multiple SQL Injection Vulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16620",
          "name" : "16620",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0522",
          "name" : "ADV-2006-0522",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24567",
          "name" : "phpmysqltimesheet-multiple-sql-injection(24567)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple SQL injection vulnerabilities in Carey Briggs PHP/MYSQL Timesheet 1 and 2 allow remote attackers to execute arbitrary SQL commands via the (1) yr, (2) month, (3) day, and (4) job parameters in (a) index.php and (b) changehrs.php."
        }, {
          "lang" : "en",
          "value" : "The vendor has supplied a patch which is available at:\r\nhttp://www.hotscripts.com/Detailed/51138.html"
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:carey_briggs:php_mysql_timesheet:1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:carey_briggs:php_mysql_timesheet:2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-15T11:06Z",
    "lastModifiedDate" : "2018-10-19T15:45Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0693",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "roberto_butti",
            "product" : {
              "product_data" : [ {
                "product_name" : "calimba",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.99.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.99.2_beta",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18856",
          "name" : "18856",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/453",
          "name" : "453",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.evuln.com/vulns/68/summary.html",
          "name" : "http://www.evuln.com/vulns/68/summary.html",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/425364/100/0/threaded",
          "name" : "20060217 [eVuln] CALimba Authentication Bypass Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16632",
          "name" : "16632",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0523",
          "name" : "ADV-2006-0523",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24578",
          "name" : "calimba-rbauth-sql-injection(24578)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple SQL injection vulnerabilities in rb_auth.php in Roberto Butti CALimba 0.99.2 beta and earlier allow remote attackers to execute arbitrary SQL commands and bypass login authentication via the (1) login and (2) password parameters."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:roberto_butti:calimba:0.99.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:roberto_butti:calimba:0.99.2_beta:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-15T11:06Z",
    "lastModifiedDate" : "2018-10-19T15:45Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0694",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ansilove",
            "product" : {
              "product_data" : [ {
                "product_name" : "ansilove",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.01",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.02",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18810",
          "name" : "18810",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://sourceforge.net/project/shownotes.php?release_id=392826",
          "name" : "http://sourceforge.net/project/shownotes.php?release_id=392826",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16603",
          "name" : "16603",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0536",
          "name" : "ADV-2006-0536",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24681",
          "name" : "ansilove-load-information-disclosure(24681)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the loaders (load_*.php) in Ansilove before 1.03 allows remote attackers to read arbitrary files via unspecified vectors involving \"converting files accessible by the webserver\"."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ansilove:ansilove:1.01:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ansilove:ansilove:1.02:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-15T11:06Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0695",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ansilove",
            "product" : {
              "product_data" : [ {
                "product_name" : "ansilove",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.01",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.02",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18810",
          "name" : "18810",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://sourceforge.net/project/shownotes.php?release_id=392826",
          "name" : "http://sourceforge.net/project/shownotes.php?release_id=392826",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16603",
          "name" : "16603",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0536",
          "name" : "ADV-2006-0536",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24684",
          "name" : "ansilove-filename-code-execution(24684)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Ansilove before 1.03 does not filter uploaded file extensions, which allows remote attackers to execute arbitrary code by uploading arbitrary files with dangerous extensions, then accessing them directly in the upload directory."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ansilove:ansilove:1.01:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ansilove:ansilove:1.02:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-15T11:06Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0696",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "zen_cart",
            "product" : {
              "product_data" : [ {
                "product_name" : "zen_cart",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.1d",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.2d",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.3d",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.4d",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.0d",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.1_patch1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.1d",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.2d",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.3d",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.4.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.4d",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.5d",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.6d",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18801",
          "name" : "18801",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://sourceforge.net/project/shownotes.php?release_id=392886",
          "name" : "http://sourceforge.net/project/shownotes.php?release_id=392886",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.osvdb.org/23110",
          "name" : "23110",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0546",
          "name" : "ADV-2006-0546",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24701",
          "name" : "zencart-multiple-sql-injection(24701)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in Zen Cart before 1.2.7 allows remote attackers to execute arbitrary SQL commands via unspecified vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:zen_cart:zen_cart:1.1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:zen_cart:zen_cart:1.1.1d:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:zen_cart:zen_cart:1.1.2d:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:zen_cart:zen_cart:1.1.3d:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:zen_cart:zen_cart:1.1.4d:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:zen_cart:zen_cart:1.2.0d:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:zen_cart:zen_cart:1.2.1_patch1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:zen_cart:zen_cart:1.2.1d:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:zen_cart:zen_cart:1.2.2d:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:zen_cart:zen_cart:1.2.3d:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:zen_cart:zen_cart:1.2.4.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:zen_cart:zen_cart:1.2.4d:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:zen_cart:zen_cart:1.2.5d:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:zen_cart:zen_cart:1.2.6d:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-15T11:06Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0697",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "zen-cart",
            "product" : {
              "product_data" : [ {
                "product_name" : "zen_cart",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.0d",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.1d",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.2d",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.3d",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.4.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.4d",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.5d",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.6d",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-264"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18801",
          "name" : "18801",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://sourceforge.net/project/shownotes.php?release_id=392886",
          "name" : "http://sourceforge.net/project/shownotes.php?release_id=392886",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0546",
          "name" : "ADV-2006-0546",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Zen Cart before 1.2.7 does not protect the admin/includes directory, which allows remote attackers to cause unknown impact via unspecified vectors, probably direct requests."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:zen-cart:zen_cart:1.1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:zen-cart:zen_cart:1.1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:zen-cart:zen_cart:1.2.0d:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:zen-cart:zen_cart:1.2.1:patch1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:zen-cart:zen_cart:1.2.1d:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:zen-cart:zen_cart:1.2.2d:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:zen-cart:zen_cart:1.2.3d:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:zen-cart:zen_cart:1.2.4.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:zen-cart:zen_cart:1.2.4d:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:zen-cart:zen_cart:1.2.5d:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:zen-cart:zen_cart:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.2.6d"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-15T11:06Z",
    "lastModifiedDate" : "2013-01-03T05:00Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0698",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "zen_cart",
            "product" : {
              "product_data" : [ {
                "product_name" : "zen_cart",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.1d",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.2d",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.3d",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.4d",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.0d",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.1_patch1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.1d",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.2d",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.3d",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.4.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.4d",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.5d",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.6d",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18801",
          "name" : "18801",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://sourceforge.net/project/shownotes.php?release_id=392886",
          "name" : "http://sourceforge.net/project/shownotes.php?release_id=392886",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0546",
          "name" : "ADV-2006-0546",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24701",
          "name" : "zencart-multiple-sql-injection(24701)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerabilities in Zen Cart before 1.2.7 allow remote attackers to cause unknown impact via unspecified vectors related to \"other attempted exploits\" other than SQL injection."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:zen_cart:zen_cart:1.1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:zen_cart:zen_cart:1.1.1d:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:zen_cart:zen_cart:1.1.2d:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:zen_cart:zen_cart:1.1.3d:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:zen_cart:zen_cart:1.1.4d:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:zen_cart:zen_cart:1.2.0d:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:zen_cart:zen_cart:1.2.1_patch1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:zen_cart:zen_cart:1.2.1d:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:zen_cart:zen_cart:1.2.2d:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:zen_cart:zen_cart:1.2.3d:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:zen_cart:zen_cart:1.2.4.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:zen_cart:zen_cart:1.2.4d:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:zen_cart:zen_cart:1.2.5d:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:zen_cart:zen_cart:1.2.6d:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-15T11:06Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0699",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "david_barrett",
            "product" : {
              "product_data" : [ {
                "product_name" : "qwikiwiki",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://insecurity.altervista.org/index.php?m=02&y=06&entry=entry060213-221217",
          "name" : "http://insecurity.altervista.org/index.php?m=02&y=06&entry=entry060213-221217",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18814",
          "name" : "18814",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16638",
          "name" : "16638",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0562",
          "name" : "ADV-2006-0562",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24669",
          "name" : "qwikiwiki-search-xss(24669)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in search.php in QWikiWiki 1.5, and possibly 1.5.1 and other versions, allows remote attackers to inject arbitrary web script or HTML via the query parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:david_barrett:qwikiwiki:1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:david_barrett:qwikiwiki:1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:david_barrett:qwikiwiki:1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:david_barrett:qwikiwiki:1.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:david_barrett:qwikiwiki:1.4.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:david_barrett:qwikiwiki:1.4.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:david_barrett:qwikiwiki:1.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:david_barrett:qwikiwiki:1.5.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-15T11:06Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0700",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "imagevue",
            "product" : {
              "product_data" : [ {
                "product_name" : "imagevue",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.16.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-264"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18802",
          "name" : "18802",
          "refsource" : "SECUNIA",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/424745/30/0/threaded",
          "name" : "20060211 imageVue16.1 upload vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16594",
          "name" : "16594",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0570",
          "name" : "ADV-2006-0570",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24641",
          "name" : "imagevue-multiple-information-disclosure(24641)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "imageVue 16.1 allows remote attackers to obtain folder permission settings via a direct request to dir.php, which returns an XML document that lists folders and their permissions."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:imagevue:imagevue:0.16.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-15T11:06Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0701",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "imagevue",
            "product" : {
              "product_data" : [ {
                "product_name" : "imagevue",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.16.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18802",
          "name" : "18802",
          "refsource" : "SECUNIA",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/424745/30/0/threaded",
          "name" : "20060211 imageVue16.1 upload vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16594",
          "name" : "16594",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0570",
          "name" : "ADV-2006-0570",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24641",
          "name" : "imagevue-multiple-information-disclosure(24641)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "readfolder.php in imageVue 16.1 allows remote attackers to list directories via modified path and ext parameters."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:imagevue:imagevue:0.16.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-15T11:06Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0702",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "imagevue",
            "product" : {
              "product_data" : [ {
                "product_name" : "imagevue",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.16.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18802",
          "name" : "18802",
          "refsource" : "SECUNIA",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/424745/30/0/threaded",
          "name" : "20060211 imageVue16.1 upload vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16594",
          "name" : "16594",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0570",
          "name" : "ADV-2006-0570",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24633",
          "name" : "imagevue-upload-file-upload(24633)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "admin/upload.php in imageVue 16.1 allows remote attackers to upload arbitrary files to certain allowed folders via .. (dot dot) sequences in the path parameter.  NOTE: due to the lack of details, the specific vulnerability type cannot be determined, although it might be due to directory traversal."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:imagevue:imagevue:0.16.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-15T11:06Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0703",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "imagevue",
            "product" : {
              "product_data" : [ {
                "product_name" : "imagevue",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.16.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18802",
          "name" : "18802",
          "refsource" : "SECUNIA",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/429",
          "name" : "429",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/424745/30/0/threaded",
          "name" : "20060211 imageVue16.1 upload vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/440586/100/100/threaded",
          "name" : "20060719 Re: imageVue16.1 upload vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/450047/100/100/threaded",
          "name" : "20061029 Re: imageVue16.1 upload vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16594",
          "name" : "16594",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0570",
          "name" : "ADV-2006-0570",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24642",
          "name" : "imagevue-index-sql-injection(24642)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in index.php in imageVue 16.1 has unknown impact, probably a cross-site scripting (XSS) vulnerability involving the query string that is not quoted when inserted into style and body tags, as demonstrated using a bgcol parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:imagevue:imagevue:0.16.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-15T11:06Z",
    "lastModifiedDate" : "2018-10-19T15:45Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0704",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ie",
            "product" : {
              "product_data" : [ {
                "product_name" : "ie_integrator",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.4.220114",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18813",
          "name" : "18813",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.irmplc.com/advisory016.htm",
          "name" : "http://www.irmplc.com/advisory016.htm",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0568",
          "name" : "ADV-2006-0568",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24714",
          "name" : "ieintegrator-error-information-disclosure(24714)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "iE Integrator 4.4.220114, when configured without a \"bespoke error page\" in acm.ini, allows remote attackers to obtain sensitive information via a URL that calls a non-existent .aspx script in the integrator/apps directory, which results in an error message that displays the installation path, web server name, IP, and port, session cookie information, and the IIS system username."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ie:ie_integrator:4.4.220114:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:H/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "HIGH",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 2.6
        },
        "severity" : "LOW",
        "exploitabilityScore" : 4.9,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-15T11:06Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0705",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "attachmatewrq",
            "product" : {
              "product_data" : [ {
                "product_name" : "reflection_for_secure_it_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "f-secure",
            "product" : {
              "product_data" : [ {
                "product_name" : "f-secure_ssh_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.1.0_build9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.2.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-134"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://marc.info/?l=bugtraq&m=120654385125315&w=2",
          "name" : "HPSBTU02322",
          "refsource" : "HP",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18828",
          "name" : "18828",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18843",
          "name" : "18843",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/24516",
          "name" : "24516",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/29552",
          "name" : "29552",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://security.gentoo.org/glsa/glsa-200703-13.xml",
          "name" : "GLSA-200703-13",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1015619",
          "name" : "1015619",
          "refsource" : "SECTRACK",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://support.wrq.com/techdocs/1882.html",
          "name" : "http://support.wrq.com/techdocs/1882.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/419241",
          "name" : "VU#419241",
          "refsource" : "CERT-VN",
          "tags" : [ "Patch", "US Government Resource" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16625",
          "name" : "16625",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16640",
          "name" : "16640",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0554",
          "name" : "ADV-2006-0554",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0555",
          "name" : "ADV-2006-0555",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/1008/references",
          "name" : "ADV-2008-1008",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24651",
          "name" : "sftp-logging-format-string(24651)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Format string vulnerability in a logging function as used by various SFTP servers, including (1) AttachmateWRQ Reflection for Secure IT UNIX Server before 6.0.0.9, (2) Reflection for Secure IT Windows Server before 6.0 build 38, (3) F-Secure SSH Server for Windows before 5.3 build 35, (4) F-Secure SSH Server for UNIX 3.0 through 5.0.8, (5) SSH Tectia Server 4.3.6 and earlier and 4.4.0, and (6) SSH Shell Server 3.2.9 and earlier, allows remote authenticated users to execute arbitrary commands via unspecified vectors, involving crafted filenames and the stat command."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:attachmatewrq:reflection_for_secure_it_server:6.0:*:unix:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:attachmatewrq:reflection_for_secure_it_server:6.0:*:win:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:f-secure:f-secure_ssh_server:3.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:f-secure:f-secure_ssh_server:3.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:f-secure:f-secure_ssh_server:3.0.1:*:unix:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:f-secure:f-secure_ssh_server:3.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:f-secure:f-secure_ssh_server:3.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:f-secure:f-secure_ssh_server:3.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:f-secure:f-secure_ssh_server:3.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:f-secure:f-secure_ssh_server:3.0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:f-secure:f-secure_ssh_server:3.0.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:f-secure:f-secure_ssh_server:3.0.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:f-secure:f-secure_ssh_server:3.0.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:f-secure:f-secure_ssh_server:3.1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:f-secure:f-secure_ssh_server:3.1.0:*:unix:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:f-secure:f-secure_ssh_server:3.1.0_build9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:f-secure:f-secure_ssh_server:3.2.0:*:unix:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:f-secure:f-secure_ssh_server:3.2.3:*:unix:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:f-secure:f-secure_ssh_server:5.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:f-secure:f-secure_ssh_server:5.1:*:win:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:f-secure:f-secure_ssh_server:5.2:*:win:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:f-secure:f-secure_ssh_server:5.3:*:win:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.5
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-15T11:06Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0706",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "gastebuch",
            "product" : {
              "product_data" : [ {
                "product_name" : "gastebuch",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.3.2",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://marc.info/?l=bugtraq&m=113986789801121&w=2",
          "name" : "20060213 XSS vulnerability in guestbook-php-script",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18849",
          "name" : "18849",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.php4scripte.de/index.php",
          "name" : "http://www.php4scripte.de/index.php",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16615",
          "name" : "16615",
          "refsource" : "BID",
          "tags" : [ "Exploit", "Patch" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0566",
          "name" : "ADV-2006-0566",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24670",
          "name" : "gastebuch-homepage-xss(24670)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting vulnerability in eintrag.php in Gästebuch (Gastebuch) before 1.3.3 allows remote attackers to inject arbitrary web script or HTML via the URL, which is used in the homepage parameter."
        }, {
          "lang" : "en",
          "value" : "This vulnerability is addressed in the following product release:\r\nGastebuch, Gastebuch, 1.3.3"
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:gastebuch:gastebuch:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.3.2"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2006-02-15T11:06Z",
    "lastModifiedDate" : "2020-02-10T21:08Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0707",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "pyblosxom",
            "product" : {
              "product_data" : [ {
                "product_name" : "pyblosxom",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.2.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.1",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-200"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18858",
          "name" : "18858",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://sourceforge.net/project/shownotes.php?release_id=391800",
          "name" : "http://sourceforge.net/project/shownotes.php?release_id=391800",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16641",
          "name" : "16641",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0571",
          "name" : "ADV-2006-0571",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24730",
          "name" : "pyblosxom-pathinfo-information-disclosure(24730)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "PyBlosxom before 1.3.2, when running on certain webservers, allows remote attackers to read arbitrary files via an HTTP request with multiple leading / (slash) characters, which is accessed using the PATH_INFO variable."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pyblosxom:pyblosxom:1.2.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pyblosxom:pyblosxom:1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pyblosxom:pyblosxom:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.3.1"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-15T11:06Z",
    "lastModifiedDate" : "2017-07-20T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0708",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "nullsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "winamp",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.01",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.02",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.03",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.04",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.05",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.06",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.07",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.08c",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.08d",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.08e",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.09",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.091",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.093",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.094",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://forums.winamp.com/showthread.php?s=&threadid=238648",
          "name" : "http://forums.winamp.com/showthread.php?s=&threadid=238648",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/444",
          "name" : "444",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/492",
          "name" : "492",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1015621",
          "name" : "1015621",
          "refsource" : "SECTRACK",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/424903/100/0/threaded",
          "name" : "20060213 New winamp m3u/pls .WMA & .M3U Extension overflows",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16623",
          "name" : "16623",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0613",
          "name" : "ADV-2006-0613",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24739",
          "name" : "winamp-pls-file1-bo(24739)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24740",
          "name" : "winamp-m3u-wma-bo(24740)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24741",
          "name" : "winamp-m3u-filename-bo(24741)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple buffer overflows in NullSoft Winamp 5.13 and earlier allow remote attackers to execute arbitrary code via (1) an m3u file containing a long URL ending in .wma, (2) a pls file containing a File1 field with a long URL ending in .wma, or (3) an m3u file with a long filename, variants of CVE-2005-3188 and CVE-2006-0476."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:nullsoft:winamp:5.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:nullsoft:winamp:5.01:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:nullsoft:winamp:5.02:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:nullsoft:winamp:5.03:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:nullsoft:winamp:5.04:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:nullsoft:winamp:5.05:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:nullsoft:winamp:5.06:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:nullsoft:winamp:5.07:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:nullsoft:winamp:5.08c:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:nullsoft:winamp:5.08d:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:nullsoft:winamp:5.08e:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:nullsoft:winamp:5.09:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:nullsoft:winamp:5.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:nullsoft:winamp:5.12:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:nullsoft:winamp:5.13:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:nullsoft:winamp:5.091:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:nullsoft:winamp:5.093:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:nullsoft:winamp:5.094:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2006-02-15T11:06Z",
    "lastModifiedDate" : "2018-10-19T15:45Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0709",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "metamail_corporation",
            "product" : {
              "product_data" : [ {
                "product_name" : "metamail",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.7.50",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=352482",
          "name" : "http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=352482",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18796",
          "name" : "18796",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18987",
          "name" : "18987",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/19000",
          "name" : "19000",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/19130",
          "name" : "19130",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/19226",
          "name" : "19226",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/19304",
          "name" : "19304",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1015654",
          "name" : "1015654",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2006/dsa-995",
          "name" : "DSA-995",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.gentoo.org/security/en/glsa/glsa-200603-16.xml",
          "name" : "GLSA-200603-16",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://www.novell.com/linux/security/advisories/2006_05_sr.html",
          "name" : "SUSE-SR:2006:005",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2006-0217.html",
          "name" : "RHSA-2006:0217",
          "refsource" : "REDHAT",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16611",
          "name" : "16611",
          "refsource" : "BID",
          "tags" : [ "Exploit", "Patch" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0565",
          "name" : "ADV-2006-0565",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://wwwnew.mandriva.com/security/advisories?name=MDKSA-2006:047",
          "name" : "MDKSA-2006:047",
          "refsource" : "MANDRIVA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24702",
          "name" : "metamail-boundary-bo(24702)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Buffer overflow in Metamail 2.7-50 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via e-mail messages with a long boundary attribute, a different vulnerability than CVE-2004-0105."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:metamail_corporation:metamail:2.7.50:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-15T11:06Z",
    "lastModifiedDate" : "2017-07-20T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0710",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "isode",
            "product" : {
              "product_data" : [ {
                "product_name" : "m-vault_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11.3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.immunitysec.com/pipermail/dailydave/2006-February/002925.html",
          "name" : "[Dailydave] 20060213 eddy 0day",
          "refsource" : "MLIST",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18818",
          "name" : "18818",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16635",
          "name" : "16635",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0567",
          "name" : "ADV-2006-0567",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24700",
          "name" : "isode-mvault-ldap-dos(24700)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Double free vulnerability in isode.eddy in Isode M-Vault Server 11.3 allows remote attackers to execute arbitrary code via a crafted LDAP request, as demonstrated by ProtoVer Sample LDAP."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:isode:m-vault_server:11.3:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-15T11:06Z",
    "lastModifiedDate" : "2017-07-20T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0711",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "neomail",
            "product" : {
              "product_data" : [ {
                "product_name" : "neomail",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.28",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18785",
          "name" : "18785",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/secunia_research/2006-3/advisory/",
          "name" : "http://secunia.com/secunia_research/2006-3/advisory/",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://sourceforge.net/project/shownotes.php?release_id=392562&group_id=2874",
          "name" : "http://sourceforge.net/project/shownotes.php?release_id=392562&group_id=2874",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16651",
          "name" : "16651",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0564",
          "name" : "ADV-2006-0564",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24737",
          "name" : "neomail-neomailprefs-bypass-security(24737)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The (1) addfolder and (2) deletefolder functions in neomail-prefs.pl in NeoMail 1.28 do not validate the Session ID, which allows remote attackers to add and delete arbitrary files, when configured with homedirfolders and homedirspools disabled."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:neomail:neomail:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.28"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-15T11:06Z",
    "lastModifiedDate" : "2017-07-20T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0712",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "squishdot",
            "product" : {
              "product_data" : [ {
                "product_name" : "squishdot",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.7.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18868",
          "name" : "18868",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16667",
          "name" : "16667",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.squishdot.org/1139510883",
          "name" : "http://www.squishdot.org/1139510883",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0551",
          "name" : "ADV-2006-0551",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24659",
          "name" : "squishdot-mailhtml-header-injection(24659)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "mail_html template in Squishdot 1.5.0 and earlier does not properly validate the (1) email and (2) title variables, which allows remote attackers to bypass spam filters by injecting SMTP headers, probably due to a CRLF injection vulnerability."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:squishdot:squishdot:0.7.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:squishdot:squishdot:1.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:squishdot:squishdot:1.1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:squishdot:squishdot:1.2.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:squishdot:squishdot:1.4.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:squishdot:squishdot:1.4.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:squishdot:squishdot:1.5.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-15T11:06Z",
    "lastModifiedDate" : "2017-07-20T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0713",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "linpha",
            "product" : {
              "product_data" : [ {
                "product_name" : "linpha",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.9.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.9.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.9.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.9.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.9.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://retrogod.altervista.org/linpha_10_local.html",
          "name" : "http://retrogod.altervista.org/linpha_10_local.html",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://secunia.com/advisories/18808",
          "name" : "18808",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/426",
          "name" : "426",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/424729/100/0/threaded",
          "name" : "20060211 Linpha <= 1.0 multiple arbitrary local inclusion",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16592",
          "name" : "16592",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0535",
          "name" : "ADV-2006-0535",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24663",
          "name" : "linpha-index-file-include(24663)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Directory traversal vulnerability in LinPHA 1.0 allows remote attackers to include arbitrary files via .. (dot dot) sequences in the (1) lang parameter in docs/index.php and the language parameter in (2) install/install.php, (3) install/sec_stage_install.php, (4) install/third_stage_install.php, and (5) install/forth_stage_install.php.  NOTE: direct static code injection is resultant from this issue, as demonstrated by inserting PHP code into the username, which is inserted into linpha.log, which is accessible from the directory traversal."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:linpha:linpha:0.9.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:linpha:linpha:0.9.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:linpha:linpha:0.9.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:linpha:linpha:0.9.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:linpha:linpha:0.9.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:linpha:linpha:1.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-15T11:06Z",
    "lastModifiedDate" : "2018-10-19T15:45Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0714",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "flyspray",
            "product" : {
              "product_data" : [ {
                "product_name" : "flyspray",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.9.7",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://retrogod.altervista.org/egs_10rc4_php5_incl_xpl.html",
          "name" : "http://retrogod.altervista.org/egs_10rc4_php5_incl_xpl.html",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://secunia.com/advisories/18847",
          "name" : "18847",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/432",
          "name" : "432",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/424902/100/0/threaded",
          "name" : "20060213 EGS Enterprise Groupware System 1.0 rc4 remote commands execution & FlySpray 0.9.7 remote commands execution",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16618",
          "name" : "16618",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0569",
          "name" : "ADV-2006-0569",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24735",
          "name" : "flyspray-adodbpath-file-include(24735)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Directory traversal vulnerability in the installation file (sql/install-0.9.7.php) in Flyspray 0.9.7 allows remote attackers to include arbitrary files via a .. (dot dot) sequence in the adodbpath parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:flyspray:flyspray:0.9.7:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-15T11:06Z",
    "lastModifiedDate" : "2018-10-19T15:45Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0715",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "solucija",
            "product" : {
              "product_data" : [ {
                "product_name" : "snews",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://archives.neohapsis.com/archives/fulldisclosure/2006-02/0297.html",
          "name" : "20060214 XSS and SQL injection in sNews",
          "refsource" : "FULLDISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/424958/100/0/threaded",
          "name" : "20060214 XSS bugs and SQL injection in sNews",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16647",
          "name" : "16647",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24674",
          "name" : "snews-comment-xss(24674)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in sNews 1.3 allows remote attackers to inject arbitrary web script or HTML via the comment field."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:solucija:snews:1.3:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-15T11:06Z",
    "lastModifiedDate" : "2018-10-19T15:45Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0716",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "solucija",
            "product" : {
              "product_data" : [ {
                "product_name" : "snews",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://archives.neohapsis.com/archives/fulldisclosure/2006-02/0297.html",
          "name" : "20060214 XSS and SQL injection in sNews",
          "refsource" : "FULLDISC",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/431",
          "name" : "431",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/424958/100/0/threaded",
          "name" : "20060214 XSS bugs and SQL injection in sNews",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16647",
          "name" : "16647",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24675",
          "name" : "snews-index-sql-injection(24675)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in index.php in sNews 1.3 allows remote attackers to execute arbitrary SQL commands via the (1) category and (2) id parameters."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:solucija:snews:1.3:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-15T11:06Z",
    "lastModifiedDate" : "2018-10-19T15:45Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0717",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "tivoli_directory_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.immunitysec.com/pipermail/dailydave/2006-February/002921.html",
          "name" : "[Dailydave] 20060211 IBM Tivoli Directory Server 0day",
          "refsource" : "MLIST",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18779",
          "name" : "18779",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1015653",
          "name" : "1015653",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16593",
          "name" : "16593",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0537",
          "name" : "ADV-2006-0537",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www-1.ibm.com/support/docview.wss?uid=swg21230820",
          "name" : "http://www-1.ibm.com/support/docview.wss?uid=swg21230820",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24619",
          "name" : "tivoli-directory-ldap-dos(24619)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "IBM Tivoli Directory Server 6.0 allows remote attackers to cause a denial of service (crash) via a crafted LDAP request, as demonstrated by test 2532 in the ProtoVer Sample LDAP test suite."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tivoli_directory_server:6.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-15T11:06Z",
    "lastModifiedDate" : "2017-07-20T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0718",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "avaya",
            "product" : {
              "product_data" : [ {
                "product_name" : "vsu_100",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.2.40",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "vsu_10000",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.2.40",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "vsu_2000",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.2.40",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "vsu_7500",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.2.40",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "csu_5000",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.2.40",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18836",
          "name" : "18836",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://support.avaya.com/elmodocs2/security/ASA-2006-043.htm",
          "name" : "http://support.avaya.com/elmodocs2/security/ASA-2006-043.htm",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/226364",
          "name" : "VU#226364",
          "refsource" : "CERT-VN",
          "tags" : [ "Third Party Advisory", "US Government Resource" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16613",
          "name" : "16613",
          "refsource" : "BID",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The Internet Key Exchange version 1 (IKEv1) implementation in Avaya VSU 100, 2000, 7500, 10000, and CSU 5000, when running IPSec, allows remote attackers to cause a denial of service (crash) via certain IKE packets, as demonstrated by the PROTOS ISAKMP Test Suite for IKEv1. NOTE: due to the lack of details in the advisory, it is unclear which of CVE-2005-3666, CVE-2005-3667, and/or CVE-2005-3668 this issue applies to."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:avaya:vsu_100:3.2.40:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:avaya:vsu_10000:3.2.40:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:avaya:vsu_2000:3.2.40:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:avaya:vsu_7500:3.2.40:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:avaya:csu_5000:3.2.40:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-15T21:02Z",
    "lastModifiedDate" : "2008-09-05T21:00Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0719",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "deltascripts",
            "product" : {
              "product_data" : [ {
                "product_name" : "php_classifieds",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.18",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.19",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.20",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18881",
          "name" : "18881",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/424",
          "name" : "424",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.deltascripts.com/board/viewtopic.php?id=7234",
          "name" : "http://www.deltascripts.com/board/viewtopic.php?id=7234",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/424955/100/0/threaded",
          "name" : "20060214 SQL injection in PHP Classifieds 6.20",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16642",
          "name" : "16642",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0600",
          "name" : "ADV-2006-0600",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in member_login.php in PHP Classifieds 6.18 through 6.20 allows remote attackers to execute arbitrary SQL commands via the (1) username parameter, which is used by the E-mail address field, and (2) password parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:deltascripts:php_classifieds:6.18:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:deltascripts:php_classifieds:6.19:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:deltascripts:php_classifieds:6.20:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-15T22:06Z",
    "lastModifiedDate" : "2018-10-19T15:45Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0720",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "nullsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "winamp",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.13",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://forums.winamp.com/showthread.php?threadid=238648",
          "name" : "http://forums.winamp.com/showthread.php?threadid=238648",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/476",
          "name" : "476",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1015675",
          "name" : "1015675",
          "refsource" : "SECTRACK",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.nsfocus.com/english/homepage/research/0601.htm",
          "name" : "http://www.nsfocus.com/english/homepage/research/0601.htm",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/425888/100/0/threaded",
          "name" : "20060223 NSFOCUS SA2006-01 : Winamp m3u File Processing Buffer Overflow Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16785",
          "name" : "16785",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24740",
          "name" : "winamp-m3u-wma-bo(24740)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Stack-based buffer overflow in Nullsoft Winamp 5.12 and 5.13 allows user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted .m3u file that causes an incorrect strncpy function call when the player pauses or stops the file."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:nullsoft:winamp:5.12:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:nullsoft:winamp:5.13:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:H/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "HIGH",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.6
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 4.9,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2006-02-23T21:02Z",
    "lastModifiedDate" : "2018-10-19T15:45Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0721",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "runcms",
            "product" : {
              "product_data" : [ {
                "product_name" : "runcms",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3a",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3a2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://hamid.ir/security/runcms.txt",
          "name" : "http://hamid.ir/security/runcms.txt",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18831",
          "name" : "18831",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1015626",
          "name" : "1015626",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.runcms.org/public/modules/forum/viewtopic.php?topic_id=4003&forum=18",
          "name" : "http://www.runcms.org/public/modules/forum/viewtopic.php?topic_id=4003&forum=18",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/425293/100/0/threaded",
          "name" : "20060216 RUNCMS 1.3a SQL injection",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16652",
          "name" : "16652",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0572",
          "name" : "ADV-2006-0572",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24676",
          "name" : "runcms-pmlite-sql-injection(24676)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in pmlite.php in RunCMS 1.2 and 1.3a allows remote attackers to execute arbitrary SQL commands via the to_userid parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:runcms:runcms:1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:runcms:runcms:1.3a:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:runcms:runcms:1.3a2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-16T11:02Z",
    "lastModifiedDate" : "2018-10-19T15:45Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0722",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "reamday_enterprises",
            "product" : {
              "product_data" : [ {
                "product_name" : "magic_downloads",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.1.3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://evuln.com/vulns/73/summary.html",
          "name" : "http://evuln.com/vulns/73/summary.html",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18877",
          "name" : "18877",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/468",
          "name" : "468",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/425601/30/6830/threaded",
          "name" : "20060221 [eVuln] Magic Downloads Unauthorized Data Modification",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16665",
          "name" : "16665",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0602",
          "name" : "ADV-2006-0602",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24615",
          "name" : "magicdownloads-settings-access(24615)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "settings.php in Reamday Enterprises Magic Downloads 1.1.3, when register_globals is enabled, allows remote attackers to modify program behavior, potentially bypassing authentication controls, via modified (1) action, (2) passwd, (3) admin_password, (4) new_passwd, and (5) confirm_passwd variables, which are not initialized."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:reamday_enterprises:magic_downloads:1.1.3:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:H/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "HIGH",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 2.6
        },
        "severity" : "LOW",
        "exploitabilityScore" : 4.9,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-16T11:02Z",
    "lastModifiedDate" : "2018-10-19T15:45Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0723",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "reamday_enterprises",
            "product" : {
              "product_data" : [ {
                "product_name" : "magic_news_lite",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.2.3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-94"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://evuln.com/vulns/72/summary.html",
          "name" : "http://evuln.com/vulns/72/summary.html",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18878",
          "name" : "18878",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16660",
          "name" : "16660",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16665",
          "name" : "16665",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0603",
          "name" : "ADV-2006-0603",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24608",
          "name" : "magicnewslite-preview-file-include(24608)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "PHP remote file inclusion vulnerability in preview.php in Reamday Enterprises Magic News Lite 1.2.3, when register_globals is enabled, allows remote attackers to include arbitrary files via a URL in the php_script_path parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:reamday_enterprises:magic_news_lite:1.2.3:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:H/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "HIGH",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 2.6
        },
        "severity" : "LOW",
        "exploitabilityScore" : 4.9,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-16T11:02Z",
    "lastModifiedDate" : "2017-07-20T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0724",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "reamday_enterprises",
            "product" : {
              "product_data" : [ {
                "product_name" : "magic_news_lite",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.2.3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://evuln.com/vulns/72/summary.html",
          "name" : "http://evuln.com/vulns/72/summary.html",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18878",
          "name" : "18878",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16665",
          "name" : "16665",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0603",
          "name" : "ADV-2006-0603",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24610",
          "name" : "magicnewslite-profile-access(24610)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "profile.php in Reamday Enterprises Magic News Lite 1.2.3, when register_globals is enabled, allows remote attackers to modify program behavior, potentially bypassing authentication controls, via modified (1) action, (2) passwd, (3) admin_password, (4) new_passwd, and (5) confirm_passwd variables, which are not initialized."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:reamday_enterprises:magic_news_lite:1.2.3:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:H/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "HIGH",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 2.6
        },
        "severity" : "LOW",
        "exploitabilityScore" : 4.9,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-16T11:02Z",
    "lastModifiedDate" : "2017-07-20T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0725",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "plume-cms",
            "product" : {
              "product_data" : [ {
                "product_name" : "plume_cms",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-94"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://plume-cms.net/news/77-Security-Notice-Please-Update-Your-Prependphp-File",
          "name" : "http://plume-cms.net/news/77-Security-Notice-Please-Update-Your-Prependphp-File",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18883",
          "name" : "18883",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1015624",
          "name" : "1015624",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/23204",
          "name" : "23204",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16662",
          "name" : "16662",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0599",
          "name" : "ADV-2006-0599",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24697",
          "name" : "plumecms-prepend-file-include(24697)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/27699",
          "name" : "plumecms-frontinc-prepend-file-include(27699)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "PHP remote file inclusion vulnerability in prepend.php in Plume CMS 1.0.2, when register_globals is enabled, allows remote attackers to include arbitrary files via a URL in the _PX_config[manager_path] parameter.  NOTE: this is a different executable and affected version than CVE-2006-2645."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:plume-cms:plume_cms:1.0.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-16T11:02Z",
    "lastModifiedDate" : "2017-07-20T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0726",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "cpg-nuke",
            "product" : {
              "product_data" : [ {
                "product_name" : "dragonfly_cms",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9.0.6.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://dragonflycms.org/cvs/html/includes/functions/linking.php?b=9.19.2",
          "name" : "http://dragonflycms.org/cvs/html/includes/functions/linking.php?b=9.19.2",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://dragonflycms.org/cvs/html/includes/functions/linking.php?d=9.23-9.22",
          "name" : "http://dragonflycms.org/cvs/html/includes/functions/linking.php?d=9.23-9.22",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://dragonflycms.org/Forums/viewtopic/t=14751.html",
          "name" : "http://dragonflycms.org/Forums/viewtopic/t=14751.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://dragonflycms.org/Forums/viewtopic/t=14877/postdays=0/postorder=asc/start=15.html",
          "name" : "http://dragonflycms.org/Forums/viewtopic/t=14877/postdays=0/postorder=asc/start=15.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18919",
          "name" : "18919",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/23060",
          "name" : "23060",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16781",
          "name" : "16781",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0688",
          "name" : "ADV-2006-0688",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24842",
          "name" : "cpg-dragonfly-linking-xss(24842)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in linking.php in CPG-Nuke Dragonfly CMS 9.0.6.1 allows remote attackers to inject arbitrary web script or HTML via a URI that is generated when creating a list of online users."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cpg-nuke:dragonfly_cms:9.0.6.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-16T11:02Z",
    "lastModifiedDate" : "2017-07-20T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0727",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "musox",
            "product" : {
              "product_data" : [ {
                "product_name" : "df_msanalysis",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://dragonflycms.org/cvs/html/includes/functions/linking.php?b=9.19.2",
          "name" : "http://dragonflycms.org/cvs/html/includes/functions/linking.php?b=9.19.2",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://dragonflycms.org/cvs/html/includes/functions/linking.php?d=9.23-9.22",
          "name" : "http://dragonflycms.org/cvs/html/includes/functions/linking.php?d=9.23-9.22",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://dragonflycms.org/Forums/viewtopic/t=14751.html",
          "name" : "http://dragonflycms.org/Forums/viewtopic/t=14751.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://dragonflycms.org/Forums/viewtopic/t=14877/postdays=0/postorder=asc/start=15.html",
          "name" : "http://dragonflycms.org/Forums/viewtopic/t=14877/postdays=0/postorder=asc/start=15.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/23060",
          "name" : "23060",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/23250",
          "name" : "23250",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16783",
          "name" : "16783",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0688",
          "name" : "ADV-2006-0688",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in mstrack.php in MusOX DF MSAnalysis (DFMSA), as used in some environments that use CPG-Nuke Dragonfly CMS, allows remote attackers to trigger path disclosure from a SQL syntax error, and possibly execute arbitrary SQL commands, via certain query data, probably involving the profile name."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:musox:df_msanalysis:1.0.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-16T11:02Z",
    "lastModifiedDate" : "2011-03-08T02:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0728",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "webspell",
            "product" : {
              "product_data" : [ {
                "product_name" : "webspell",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.01.00",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18885",
          "name" : "18885",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16673",
          "name" : "16673",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0606",
          "name" : "ADV-2006-0606",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.webspell.org/index.php?site=news_comments&newsID=49&lang=en",
          "name" : "http://www.webspell.org/index.php?site=news_comments&newsID=49&lang=en",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24708",
          "name" : "webspell-search-sql-injection(24708)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in search.php in webSPELL 4.01.00 and earlier allows remote attackers to inject arbitrary SQL commands via the title_op parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:webspell:webspell:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "4.01.00"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-16T11:02Z",
    "lastModifiedDate" : "2017-07-20T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0729",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "teca_scripts",
            "product" : {
              "product_data" : [ {
                "product_name" : "teca_diary",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "personal_1.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18876",
          "name" : "18876",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/477",
          "name" : "477",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1015674",
          "name" : "1015674",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.evuln.com/vulns/75/summary.html",
          "name" : "http://www.evuln.com/vulns/75/summary.html",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/425892/30/6800/threaded",
          "name" : "20060223 [eVuln] Teca Diary PE SQL Injection Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16686",
          "name" : "16686",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0615",
          "name" : "ADV-2006-0615",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24643",
          "name" : "tecadiary-functions-sql-injection(24643)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in functions.php in Teca Diary PE 1.0 allows remote attackers to execute arbitrary SQL commands via the (1) yy, (2) mm, and (3) dd parameters."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:teca_scripts:teca_diary:personal_1.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-16T11:02Z",
    "lastModifiedDate" : "2018-10-19T15:45Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0730",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "timo_sirainen",
            "product" : {
              "product_data" : [ {
                "product_name" : "dovecot",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0beta2",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          }, {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18870",
          "name" : "18870",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.dovecot.org/list/dovecot/2006-February/011367.html",
          "name" : "[Dovecot] 20060208 1.0beta3 released",
          "refsource" : "MLIST",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16672",
          "name" : "16672",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0549",
          "name" : "ADV-2006-0549",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24709",
          "name" : "dovecot-append-dos(24709)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple unspecified vulnerabilities in Dovecot before 1.0beta3 allow remote attackers to cause a denial of service (application crash or hang) via unspecified vectors involving (1) \"potential hangs\" in the APPEND command and \"potential crashes\" in (2) dovecot-auth and (3) imap/pop3-login.  NOTE: vector 2 might be related to a double free vulnerability."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:timo_sirainen:dovecot:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.0beta2"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-16T11:02Z",
    "lastModifiedDate" : "2017-07-20T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0731",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "sap",
            "product" : {
              "product_data" : [ {
                "product_name" : "business_connector",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "core_fix_7",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18880",
          "name" : "18880",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1015639",
          "name" : "1015639",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.cybsec.com/vuln/CYBSEC_Security_Pre-Advisory_Phishing_Vector_in_SAP_BC.pdf",
          "name" : "http://www.cybsec.com/vuln/CYBSEC_Security_Pre-Advisory_Phishing_Vector_in_SAP_BC.pdf",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/425056/100/0/threaded",
          "name" : "20060215 CYBSEC - Security Pre-Advisory: Phishing Vector in SAP BC",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/434012/30/4980/threaded",
          "name" : "20060515 CYBSEC - Security Advisory: Phishing Vector in SAP BC (BusinessConnector)",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16671",
          "name" : "16671",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0611",
          "name" : "ADV-2006-0611",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24751",
          "name" : "sapbc-admin-spoofing(24751)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "WmRoot/adapter-index.dsp in SAP Business Connector Core Fix 7 and earlier allows remote attackers to conduct spoofing (phishing) attacks via an absolute URL in the url parameter, which loads the URL inside a frame."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sap:business_connector:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "core_fix_7"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:H/Au:N/C:P/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "HIGH",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 4.9,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2006-02-16T11:02Z",
    "lastModifiedDate" : "2018-10-19T15:45Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0732",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "sap",
            "product" : {
              "product_data" : [ {
                "product_name" : "business_connector",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.7",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18880",
          "name" : "18880",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1015639",
          "name" : "1015639",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1016090",
          "name" : "1016090",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1016122",
          "name" : "1016122",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.cybsec.com/vuln/CYBSEC_Security_Advisory_Arbitrary_File_Read_or_Delete_in_SAP_BC.pdf",
          "name" : "http://www.cybsec.com/vuln/CYBSEC_Security_Advisory_Arbitrary_File_Read_or_Delete_in_SAP_BC.pdf",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.cybsec.com/vuln/CYBSEC_Security_Pre-Advisory_Arbitrary_File_Read_or_Delete_in_SAP_BC.pdf",
          "name" : "http://www.cybsec.com/vuln/CYBSEC_Security_Pre-Advisory_Arbitrary_File_Read_or_Delete_in_SAP_BC.pdf",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/425048/100/0/threaded",
          "name" : "20060215 CYBSEC - Security Pre-Advisory: Arbitrary File Read/Delete in SAPBC",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/434014/30/4980/threaded",
          "name" : "20060515 CYBSEC - Security Advisory: Arbitrary File Read/Delete in SAP BC(Business Connector)",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16668",
          "name" : "16668",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0611",
          "name" : "ADV-2006-0611",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Directory traversal vulnerability in SAP Business Connector (BC) 4.6 and 4.7 allows remote attackers to read or delete arbitrary files via the fullName parameter to (1) sapbc/SAP/chopSAPLog.dsp or (2) invoke/sap.monitor.rfcTrace/deleteSingle.  Details will be updated after the grace period has ended.  NOTE: SAP Business Connector is an OEM version of webMethods Integration Server.  webMethods states that this issue can only occur when the product is installed as root/admin, and if the attacker has access to a general purpose port; however, both are discouraged in the documentation.  In addition, the attacker must already have acquired administrative privileges through other means."
        }, {
          "lang" : "en",
          "value" : "Apply patches (see SAP note 906401 and 908349)."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sap:business_connector:4.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sap:business_connector:4.7:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 6.4
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-16T11:02Z",
    "lastModifiedDate" : "2018-10-19T15:45Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0733",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "wordpress",
            "product" : {
              "product_data" : [ {
                "product_name" : "wordpress",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://myimei.com/security/2006-02-15/wordpress200autors-websitexss-attack.html",
          "name" : "http://myimei.com/security/2006-02-15/wordpress200autors-websitexss-attack.html",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/425043/100/0/threaded",
          "name" : "20060214 [myimei]WordPress2.0.0~autors?website~XSS attack",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16656",
          "name" : "16656",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24736",
          "name" : "wordpress-authorswebsite-xss(24736)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "** DISPUTED ** Cross-site scripting (XSS) vulnerability in WordPress 2.0.0 allows remote attackers to inject arbitrary web script or HTML via scriptable attributes such as (1) onfocus and (2) onblur in the \"author's website\" field.  NOTE: followup comments to the researcher's web log suggest that this issue is only exploitable by the same user who injects the XSS, so this might not be a vulnerability."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wordpress:wordpress:2.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:H/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "HIGH",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 2.6
        },
        "severity" : "LOW",
        "exploitabilityScore" : 4.9,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-16T11:02Z",
    "lastModifiedDate" : "2018-10-19T15:45Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0734",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "valve_software",
            "product" : {
              "product_data" : [ {
                "product_name" : "half-life_cstrike_dedicated_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.6_linux",
                    "version_affected" : "<="
                  }, {
                    "version_value" : "1.6_windows",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://aluigi.altervista.org/adv/csdos.txt",
          "name" : "http://aluigi.altervista.org/adv/csdos.txt",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16619",
          "name" : "16619",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/33505",
          "name" : "halflife-svcheckforduplicatenames-dos(33505)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The SV_CheckForDuplicateNames function in Valve Software Half-Life CSTRIKE Dedicated Server 1.6 and earlier allows remote authenticated users to cause a denial of service (infinite loop and daemon hang) via a backslash character at the end of a connection string to UDP port 27015."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:valve_software:half-life_cstrike_dedicated_server:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.6_linux"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:valve_software:half-life_cstrike_dedicated_server:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.6_windows"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 4.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-16T11:02Z",
    "lastModifiedDate" : "2017-07-20T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0735",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "fuzzymonkey",
            "product" : {
              "product_data" : [ {
                "product_name" : "my_blog",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.21",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.22",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.23",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.31",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.51",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.52",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.61",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.62",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.63",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.64",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "m_blom",
            "product" : {
              "product_data" : [ {
                "product_name" : "html-bbcode",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.03",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.04",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://evuln.com/vulns/79/summary.html",
          "name" : "http://evuln.com/vulns/79/summary.html",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://evuln.com/vulns/80/summary.html",
          "name" : "http://evuln.com/vulns/80/summary.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Exploit", "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://fuzzymonkey.net/forum/viewtopic.php?t=856",
          "name" : "http://fuzzymonkey.net/forum/viewtopic.php?t=856",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://menno.b10m.net/perl/dists/HTML-BBCode-1.05.tar.gz",
          "name" : "http://menno.b10m.net/perl/dists/HTML-BBCode-1.05.tar.gz",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://menno.b10m.net/perl/HTML-BBCode/Changes",
          "name" : "http://menno.b10m.net/perl/HTML-BBCode/Changes",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18905",
          "name" : "18905",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18925",
          "name" : "18925",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.evuln.com/vulns/80/summary.html",
          "name" : "http://www.evuln.com/vulns/80/summary.html",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/425087/100/0/threaded",
          "name" : "20060215 [eVuln] My Blog BBCode XSS Vulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/425113/100/0/threaded",
          "name" : "20060215 [eVuln] M. Blom HTML::BBCode perl module XSS Vulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16659",
          "name" : "16659",
          "refsource" : "BID",
          "tags" : [ "Exploit", "Patch" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0614",
          "name" : "ADV-2006-0614",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0642",
          "name" : "ADV-2006-0642",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24668",
          "name" : "myblog-bbcode-xss(24668)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in BBcode.pm in M. Blom HTML::BBCode 1.04 and earlier, as used in products such as My Blog before 1.65, allows remote attackers to inject arbitrary Javascript via a javascript URI in an (1) img or (2) url BBcode tag."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:fuzzymonkey:my_blog:1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:fuzzymonkey:my_blog:1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:fuzzymonkey:my_blog:1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:fuzzymonkey:my_blog:1.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:fuzzymonkey:my_blog:1.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:fuzzymonkey:my_blog:1.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:fuzzymonkey:my_blog:1.21:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:fuzzymonkey:my_blog:1.22:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:fuzzymonkey:my_blog:1.23:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:fuzzymonkey:my_blog:1.31:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:fuzzymonkey:my_blog:1.51:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:fuzzymonkey:my_blog:1.52:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:fuzzymonkey:my_blog:1.61:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:fuzzymonkey:my_blog:1.62:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:fuzzymonkey:my_blog:1.63:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:fuzzymonkey:my_blog:1.64:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:m_blom:html-bbcode:1.03:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:m_blom:html-bbcode:1.04:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-16T11:02Z",
    "lastModifiedDate" : "2018-10-19T15:45Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0736",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "novell",
            "product" : {
              "product_data" : [ {
                "product_name" : "linux_desktop",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "open_enterprise_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18995",
          "name" : "18995",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.novell.com/linux/security/advisories/2006_10_casa.html",
          "name" : "SUSE-SA:2006:010",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16779",
          "name" : "16779",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0693",
          "name" : "ADV-2006-0693",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Stack-based buffer overflow in the pam_micasa PAM authentication module in CASA on Novell Linux Desktop 9 and Open Enterprise Server 1 allows remote attackers to execute arbitrary code via unspecified vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:novell:linux_desktop:9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:novell:open_enterprise_server:1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-27T20:06Z",
    "lastModifiedDate" : "2020-02-24T14:15Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0737",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "estara",
            "product" : {
              "product_data" : [ {
                "product_name" : "softphone",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.0.1.47",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18872",
          "name" : "18872",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/424943/100/0/threaded",
          "name" : "20060214 eStara SIP softphone several message-processing vulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16629",
          "name" : "16629",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0607",
          "name" : "ADV-2006-0607",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24677",
          "name" : "estara-neg-integer-dos(24677)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "eStara SIP softphone allows remote attackers to cause a denial of service (crash) via a SIP OPTIONS request with a negative Expires field."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:estara:softphone:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "3.0.1.47"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-17T01:02Z",
    "lastModifiedDate" : "2018-10-19T15:46Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0738",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "estara",
            "product" : {
              "product_data" : [ {
                "product_name" : "softphone",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.0.1.47",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18872",
          "name" : "18872",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/424943/100/0/threaded",
          "name" : "20060214 eStara SIP softphone several message-processing vulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16629",
          "name" : "16629",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0607",
          "name" : "ADV-2006-0607",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24678",
          "name" : "estara-sdp-format-string(24678)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple format string vulnerabilities in eStara SIP softphone allow remote attackers to cause a denial of service (hang) via SIP INVITE requests with format string specifiers in the SDP session description, as demonstrated using (1) the field name, (2) the o field (owner/creator and session identifier), or (3) the m field (media name and transport address)."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:estara:softphone:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "3.0.1.47"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-17T01:02Z",
    "lastModifiedDate" : "2018-10-19T15:46Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0739",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "estara",
            "product" : {
              "product_data" : [ {
                "product_name" : "softphone",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.0.1.47",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18872",
          "name" : "18872",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/424943/100/0/threaded",
          "name" : "20060214 eStara SIP softphone several message-processing vulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16629",
          "name" : "16629",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0607",
          "name" : "ADV-2006-0607",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24679",
          "name" : "estara-content-length-dos(24679)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "eStara SIP softphone allows remote attackers to cause a denial of service (crash) via an INVITE request with a Content-Length field that has more than 9 digits."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:estara:softphone:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "3.0.1.47"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-17T01:02Z",
    "lastModifiedDate" : "2018-10-19T15:46Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0741",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "linux",
            "product" : {
              "product_data" : [ {
                "product_name" : "linux_kernel",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.8.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.8.1.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11_rc1_bk6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.12.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.12.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.12.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.12.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.12.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.12.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.13.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.13.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.13.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.13.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.14.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.14.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.14.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.14.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.15",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.15.5",
          "name" : "http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.15.5",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/19083",
          "name" : "19083",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/19108",
          "name" : "19108",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/19220",
          "name" : "19220",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/20237",
          "name" : "20237",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/20398",
          "name" : "20398",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/20671",
          "name" : "20671",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/20914",
          "name" : "20914",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/21136",
          "name" : "21136",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/21745",
          "name" : "21745",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/21983",
          "name" : "21983",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1015724",
          "name" : "1015724",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://support.avaya.com/elmodocs2/security/ASA-2006-161.htm",
          "name" : "http://support.avaya.com/elmodocs2/security/ASA-2006-161.htm",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://support.avaya.com/elmodocs2/security/ASA-2006-180.htm",
          "name" : "http://support.avaya.com/elmodocs2/security/ASA-2006-180.htm",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2006/dsa-1097",
          "name" : "DSA-1097",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2006/dsa-1103",
          "name" : "DSA-1103",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDKSA-2006:059",
          "name" : "MDKSA-2006:059",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDKSA-2007:025",
          "name" : "MDKSA-2007:025",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.novell.com/linux/security/advisories/2006-05-31.html",
          "name" : "SUSE-SA:2006:028",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/23607",
          "name" : "23607",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/archives/fedora-announce-list/2006-March/msg00003.html",
          "name" : "FEDORA-2006-131",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2006-0437.html",
          "name" : "RHSA-2006:0437",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2006-0493.html",
          "name" : "RHSA-2006:0493",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16925",
          "name" : "16925",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0804",
          "name" : "ADV-2006-0804",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/2554",
          "name" : "ADV-2006-2554",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/25001",
          "name" : "kernel-elf-dos(25001)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10518",
          "name" : "oval:org.mitre.oval:def:10518",
          "refsource" : "OVAL",
          "tags" : [ ]
        }, {
          "url" : "https://usn.ubuntu.com/263-1/",
          "name" : "USN-263-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Linux kernel before 2.6.15.5, when running on Intel processors, allows local users to cause a denial of service (\"endless recursive fault\") via unknown attack vectors related to a \"bad elf entry address.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.0:test1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.0:test10:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.0:test11:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.0:test2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.0:test3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.0:test4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.0:test5:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.0:test6:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.0:test7:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.0:test8:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.0:test9:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.1:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.1:rc2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.6:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.7:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.8:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.8:rc2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.8:rc3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.8.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.8.1.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.9:2.6.20:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.10:rc2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11:rc2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11:rc3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11:rc4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11.12:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11_rc1_bk6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.12:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.12:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.12:rc4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.12:rc5:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.12.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.12.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.12.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.12.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.12.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.12.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.13:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.13:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.13:rc4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.13:rc6:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.13:rc7:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.13.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.13.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.13.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.13.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.14:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.14:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.14:rc2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.14:rc3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.14:rc4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.14.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.14.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.14.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.14.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.15:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.15:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.15:rc3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.15:rc4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.15:rc5:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.15:rc6:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.15:rc7:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:H/Au:N/C:N/I:N/A:P",
          "accessVector" : "LOCAL",
          "accessComplexity" : "HIGH",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 1.2
        },
        "severity" : "LOW",
        "exploitabilityScore" : 1.9,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-03-07T02:02Z",
    "lastModifiedDate" : "2018-10-03T21:35Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0742",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "linux",
            "product" : {
              "product_data" : [ {
                "product_name" : "linux_kernel",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.8.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.8.1.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11_rc1_bk6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.12.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.12.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.12.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.12.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.12.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.12.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.13.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.13.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.13.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.13.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.14.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.14.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.14.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.14.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.15",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "ftp://patches.sgi.com/support/free/security/advisories/20060402-01-U",
          "name" : "20060402-01-U",
          "refsource" : "SGI",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/19078",
          "name" : "19078",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/19220",
          "name" : "19220",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/19607",
          "name" : "19607",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/20398",
          "name" : "20398",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/20671",
          "name" : "20671",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/20914",
          "name" : "20914",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/21136",
          "name" : "21136",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/21465",
          "name" : "21465",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/21983",
          "name" : "21983",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/22417",
          "name" : "22417",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://support.avaya.com/elmodocs2/security/ASA-2006-180.htm",
          "name" : "http://support.avaya.com/elmodocs2/security/ASA-2006-180.htm",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://support.avaya.com/elmodocs2/security/ASA-2006-200.htm",
          "name" : "http://support.avaya.com/elmodocs2/security/ASA-2006-200.htm",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2006/dsa-1097",
          "name" : "DSA-1097",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2006/dsa-1103",
          "name" : "DSA-1103",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.15.6",
          "name" : "http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.15.6",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDKSA-2006:059",
          "name" : "MDKSA-2006:059",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.novell.com/linux/security/advisories/2006-05-31.html",
          "name" : "SUSE-SA:2006:028",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/23660",
          "name" : "23660",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2006-0437.html",
          "name" : "RHSA-2006:0437",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2006-0575.html",
          "name" : "RHSA-2006:0575",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16993",
          "name" : "16993",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0856",
          "name" : "ADV-2006-0856",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/2554",
          "name" : "ADV-2006-2554",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/25068",
          "name" : "kernel-dieifkernel-dos(25068)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10742",
          "name" : "oval:org.mitre.oval:def:10742",
          "refsource" : "OVAL",
          "tags" : [ ]
        }, {
          "url" : "https://usn.ubuntu.com/263-1/",
          "name" : "USN-263-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The die_if_kernel function in arch/ia64/kernel/unaligned.c in Linux kernel 2.6.x before 2.6.15.6, possibly when compiled with certain versions of gcc, has the \"noreturn\" attribute set, which allows local users to cause a denial of service by causing user faults on Itanium systems."
        }, {
          "lang" : "en",
          "value" : "This vulnerability affects all verison of Linux kernel 2.6.x before 2.6.15.6, and may be exclusive to Itanium systems."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.0:*:64-bit_x86:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.0:*:itanium_ia64_montecito:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.0:test1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.0:test10:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.0:test11:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.0:test2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.0:test3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.0:test4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.0:test5:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.0:test6:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.0:test7:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.0:test8:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.0:test9:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.1:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.1:rc2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.6:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.7:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.8:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.8:rc2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.8:rc3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.8.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.8.1.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.8.1.5:*:386:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.8.1.5:*:686:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.8.1.5:*:686_smp:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.8.1.5:*:amd64:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.8.1.5:*:amd64_k8:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.8.1.5:*:amd64_k8_smp:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.8.1.5:*:amd64_xeon:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.8.1.5:*:k7:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.8.1.5:*:k7_smp:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.8.1.5:*:power3:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.8.1.5:*:power3_smp:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.8.1.5:*:power4:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.8.1.5:*:power4_smp:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.8.1.5:*:powerpc:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.8.1.5:*:powerpc_smp:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.9:2.6.20:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.10:rc2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11:rc2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11:rc3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11:rc4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11.12:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11_rc1_bk6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.12:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.12:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.12:rc4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.12:rc5:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.12.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.12.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.12.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.12.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.12.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.12.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.13:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.13:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.13:rc4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.13:rc6:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.13:rc7:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.13.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.13.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.13.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.13.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.14:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.14:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.14:rc2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.14:rc3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.14:rc4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.14.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.14.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.14.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.14.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.15:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.15:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.15:rc3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.15:rc4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.15:rc5:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:S/C:N/I:N/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 4.6
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 3.1,
        "impactScore" : 6.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-03-09T13:06Z",
    "lastModifiedDate" : "2018-10-03T21:35Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0743",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apache",
            "product" : {
              "product_data" : [ {
                "product_name" : "log4net",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.2.9_beta",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-134"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://issues.apache.org/jira/browse/LOG4NET-67",
          "name" : "http://issues.apache.org/jira/browse/LOG4NET-67",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/19241",
          "name" : "19241",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/22932",
          "name" : "22932",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.novell.com/linux/security/advisories/2006_26_sr.html",
          "name" : "SUSE-SR:2006:026",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/23905",
          "name" : "23905",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/17095",
          "name" : "17095",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0955",
          "name" : "ADV-2006-0955",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/25196",
          "name" : "log4net-localsyslogappender-dos(25196)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Format string vulnerability in LocalSyslogAppender in Apache log4net 1.2.9 might allow remote attackers to cause a denial of service (memory corruption and termination) via unknown vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:log4net:1.2.9_beta:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-03-09T20:02Z",
    "lastModifiedDate" : "2017-07-20T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0744",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "linux",
            "product" : {
              "product_data" : [ {
                "product_name" : "linux_kernel",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.11.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.12.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.12.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.12.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.12.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.12.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.12.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.13.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.13.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.13.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.13.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.14.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.14.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.14.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.14.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.14.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.14.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.14.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.15.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.15.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.15.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.15.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.15.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.15.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.15.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.16",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.16.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.16.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.16.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.16.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.16_rc7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6_test9_cvs",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-20"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.16.5",
          "name" : "http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.16.5",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://lwn.net/Alerts/180820/",
          "name" : "FEDORA-2006-423",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/19639",
          "name" : "19639",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/19735",
          "name" : "19735",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/20157",
          "name" : "20157",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/20237",
          "name" : "20237",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/20398",
          "name" : "20398",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/20716",
          "name" : "20716",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/20914",
          "name" : "20914",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/21136",
          "name" : "21136",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/21179",
          "name" : "21179",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/21498",
          "name" : "21498",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/21745",
          "name" : "21745",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/21983",
          "name" : "21983",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://support.avaya.com/elmodocs2/security/ASA-2006-161.htm",
          "name" : "http://support.avaya.com/elmodocs2/security/ASA-2006-161.htm",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://support.avaya.com/elmodocs2/security/ASA-2006-180.htm",
          "name" : "http://support.avaya.com/elmodocs2/security/ASA-2006-180.htm",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2006/dsa-1103",
          "name" : "DSA-1103",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDKSA-2006:086",
          "name" : "MDKSA-2006:086",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDKSA-2006:150",
          "name" : "MDKSA-2006:150",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.novell.com/linux/security/advisories/2006_42_kernel.html",
          "name" : "SUSE-SA:2006:042",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://www.novell.com/linux/security/advisories/2006_47_kernel.html",
          "name" : "SUSE-SA:2006:047",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://www.novell.com/linux/security/advisories/2006-05-31.html",
          "name" : "SUSE-SA:2006:028",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/24639",
          "name" : "24639",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2006-0437.html",
          "name" : "RHSA-2006:0437",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2006-0493.html",
          "name" : "RHSA-2006:0493",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/17541",
          "name" : "17541",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/usn-302-1",
          "name" : "USN-302-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/1390",
          "name" : "ADV-2006-1390",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/1475",
          "name" : "ADV-2006-1475",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/2554",
          "name" : "ADV-2006-2554",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/25869",
          "name" : "linux-uncanonical-addr-dos(25869)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9732",
          "name" : "oval:org.mitre.oval:def:9732",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Linux kernel before 2.6.16.5 does not properly handle uncanonical return addresses on Intel EM64T CPUs, which reports an exception in the SYSRET instead of the next instruction, which causes the kernel exception handler to run on the user stack with the wrong GS."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.0:test1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.0:test10:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.0:test11:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.0:test2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.0:test3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.0:test4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.0:test5:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.0:test6:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.0:test7:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.0:test8:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.0:test9:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.1:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.1:rc2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.1:rc3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.2:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.2:rc2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.2:rc3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.3:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.3:rc2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.3:rc3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.3:rc4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.4:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.4:rc2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.4:rc3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.5:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.5:rc2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.5:rc3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.6:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.6:rc2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.6:rc3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.7:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.7:rc2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.7:rc3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.8:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.8:rc2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.8:rc3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.8:rc4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.9:2.6.20:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.9:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.9:rc2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.9:rc3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.9:rc4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.10:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.10:rc2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.10:rc3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11:rc2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11:rc3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11:rc4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11:rc5:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.11.12:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.12:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.12:rc2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.12:rc3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.12:rc4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.12:rc5:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.12:rc6:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.12.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.12.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.12.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.12.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.12.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.12.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.13:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.13:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.13:rc2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.13:rc3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.13:rc4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.13:rc5:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.13:rc6:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.13:rc7:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.13.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.13.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.13.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.13.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.14:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.14:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.14:rc2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.14:rc3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.14:rc4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.14:rc5:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.14.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.14.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.14.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.14.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.14.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.14.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.14.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.15:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.15:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.15:rc3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.15:rc4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.15:rc5:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.15:rc6:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.15:rc7:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.15.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.15.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.15.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.15.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.15.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.15.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.15.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16:rc2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16:rc3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16:rc4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16:rc5:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16:rc6:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6.16_rc7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:2.6_test9_cvs:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:N/I:N/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 4.9
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 3.9,
        "impactScore" : 6.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-04-18T10:02Z",
    "lastModifiedDate" : "2018-10-30T16:26Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0745",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "x.org",
            "product" : {
              "product_data" : [ {
                "product_name" : "x11r6",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.9",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "x11r7",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "mandrakesoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "mandrake_linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2006",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "redhat",
            "product" : {
              "product_data" : [ {
                "product_name" : "fedora_core",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "core_5.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "sun",
            "product" : {
              "product_data" : [ {
                "product_name" : "solaris",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "suse",
            "product" : {
              "product_data" : [ {
                "product_name" : "suse_linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/19256",
          "name" : "19256",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/19307",
          "name" : "19307",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/19311",
          "name" : "19311",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/19316",
          "name" : "19316",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/19676",
          "name" : "19676",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/606",
          "name" : "606",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1015793",
          "name" : "1015793",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://sunsolve.sun.com/search/document.do?assetkey=1-26-102252-1",
          "name" : "102252",
          "refsource" : "SUNALERT",
          "tags" : [ ]
        }, {
          "url" : "http://support.avaya.com/elmodocs2/security/ASA-2006-078.htm",
          "name" : "http://support.avaya.com/elmodocs2/security/ASA-2006-078.htm",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDKSA-2006:056",
          "name" : "MDKSA-2006:056",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.novell.com/linux/security/advisories/2006_16_xorgx11server.html",
          "name" : "SUSE-SA:2006:016",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/24000",
          "name" : "24000",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/24001",
          "name" : "24001",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/archives/fedora-announce-list/2006-March/msg00026.html",
          "name" : "FEDORA-2006-172",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/428183/100/0/threaded",
          "name" : "20060320 [CVE-2006-0745] X.Org Security Advisory: privilege escalation and DoS in X11R6.9, X11R7.0",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/428230/100/0/threaded",
          "name" : "20060320 Re: [CVE-2006-0745] X.Org Security Advisory: privilege escalation and DoS in X11R6.9, X11R7.0",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/17169",
          "name" : "17169",
          "refsource" : "BID",
          "tags" : [ "Exploit", "Patch" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/1017",
          "name" : "ADV-2006-1017",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/1028",
          "name" : "ADV-2006-1028",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/25341",
          "name" : "xorg-geteuid-privilege-escalation(25341)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1697",
          "name" : "oval:org.mitre.oval:def:1697",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "X.Org server (xorg-server) 1.0.0 and later, X11R6.9.0, and X11R7.0 inadvertently treats the address of the geteuid function as if it is the return value of a call to geteuid, which allows local users to bypass intended restrictions and (1) execute arbitrary code via the -modulepath command line option or (2) overwrite arbitrary files via -logfile."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:x.org:x11r6:6.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:x.org:x11r7:1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:x.org:x11r7:1.0.1:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:mandrakesoft:mandrake_linux:2006:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:mandrakesoft:mandrake_linux:2006:*:x86_64:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:fedora_core:core_5.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:sun:solaris:10.0:*:x86:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:suse:suse_linux:10.0:*:oss:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.2
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 3.9,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-03-21T02:06Z",
    "lastModifiedDate" : "2018-10-19T15:46Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0746",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "xpdf",
            "product" : {
              "product_data" : [ {
                "product_name" : "xpdf",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/19189",
          "name" : "19189",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/19190",
          "name" : "19190",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/19264",
          "name" : "19264",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/566",
          "name" : "566",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1015751",
          "name" : "1015751",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2006/dsa-1008",
          "name" : "DSA-1008",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.kde.org/info/security/advisory-20060202-1.txt",
          "name" : "http://www.kde.org/info/security/advisory-20060202-1.txt",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDKSA-2006:054",
          "name" : "MDKSA-2006:054",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2006-0262.html",
          "name" : "RHSA-2006:0262",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/427299/100/0/threaded",
          "name" : "20060310 [KDE Security Advisory] kpdf of KDE 3.3.x heap based buffer overflow",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/17039",
          "name" : "17039",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/25146",
          "name" : "kde-kpdf-patch-bo(25146)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11441",
          "name" : "oval:org.mitre.oval:def:11441",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Certain patches for kpdf do not include all relevant patches from xpdf that were associated with CVE-2005-3627, which allows context-dependent attackers to exploit vulnerabilities that were present in CVE-2005-3627."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:xpdf:xpdf:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-03-09T00:02Z",
    "lastModifiedDate" : "2018-10-19T15:46Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0747",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "freetype",
            "product" : {
              "product_data" : [ {
                "product_name" : "freetype",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.1",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-189"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "ftp://patches.sgi.com/support/free/security/advisories/20060701-01-U",
          "name" : "20060701-01-U",
          "refsource" : "SGI",
          "tags" : [ ]
        }, {
          "url" : "http://lists.apple.com/archives/security-announce/2009/May/msg00002.html",
          "name" : "APPLE-SA-2009-05-12",
          "refsource" : "APPLE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.suse.com/archive/suse-security-announce/2006-Jun/0012.html",
          "name" : "SUSE-SA:2006:037",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/20525",
          "name" : "20525",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/20591",
          "name" : "20591",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/20638",
          "name" : "20638",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/20791",
          "name" : "20791",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/21062",
          "name" : "21062",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/21135",
          "name" : "21135",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/21385",
          "name" : "21385",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/21701",
          "name" : "21701",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/23939",
          "name" : "23939",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/35074",
          "name" : "35074",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1016522",
          "name" : "1016522",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://sunsolve.sun.com/search/document.do?assetkey=1-26-102705-1",
          "name" : "102705",
          "refsource" : "SUNALERT",
          "tags" : [ ]
        }, {
          "url" : "http://support.apple.com/kb/HT3549",
          "name" : "http://support.apple.com/kb/HT3549",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://support.avaya.com/elmodocs2/security/ASA-2006-176.htm",
          "name" : "http://support.avaya.com/elmodocs2/security/ASA-2006-176.htm",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2006/dsa-1095",
          "name" : "DSA-1095",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDKSA-2006:099",
          "name" : "MDKSA-2006:099",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2006-0500.html",
          "name" : "RHSA-2006:0500",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/436836/100/0/threaded",
          "name" : "20060612 rPSA-2006-0100-1 freetype",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/18326",
          "name" : "18326",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA09-133A.html",
          "name" : "TA09-133A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2007/0381",
          "name" : "ADV-2007-0381",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2009/1297",
          "name" : "ADV-2009-1297",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=183676",
          "name" : "https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=183676",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "https://issues.rpath.com/browse/RPL-429",
          "name" : "https://issues.rpath.com/browse/RPL-429",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9508",
          "name" : "oval:org.mitre.oval:def:9508",
          "refsource" : "OVAL",
          "tags" : [ ]
        }, {
          "url" : "https://usn.ubuntu.com/291-1/",
          "name" : "USN-291-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Integer underflow in Freetype before 2.2 allows remote attackers to cause a denial of service (crash) via a font file with an odd number of blue values, which causes the underflow when decrementing by 2 in a context that assumes an even number of values."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:freetype:freetype:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "2.1"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-05-23T10:06Z",
    "lastModifiedDate" : "2018-10-19T15:46Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0748",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "mozilla",
            "product" : {
              "product_data" : [ {
                "product_name" : "firefox",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "preview_release",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "seamonkey",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "thunderbird",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.0.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-399"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2006.26/SCOSA-2006.26.txt",
          "name" : "SCOSA-2006.26",
          "refsource" : "SCO",
          "tags" : [ ]
        }, {
          "url" : "ftp://patches.sgi.com/support/free/security/advisories/20060404-01-U.asc",
          "name" : "20060404-01-U",
          "refsource" : "SGI",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/19759",
          "name" : "19759",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/19794",
          "name" : "19794",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/19811",
          "name" : "19811",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/19821",
          "name" : "19821",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/19823",
          "name" : "19823",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/19852",
          "name" : "19852",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/19862",
          "name" : "19862",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/19863",
          "name" : "19863",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/19902",
          "name" : "19902",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/19941",
          "name" : "19941",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/19950",
          "name" : "19950",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/20051",
          "name" : "20051",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/21033",
          "name" : "21033",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/21622",
          "name" : "21622",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/22065",
          "name" : "22065",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/22066",
          "name" : "22066",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://sunsolve.sun.com/search/document.do?assetkey=1-26-102550-1",
          "name" : "102550",
          "refsource" : "SUNALERT",
          "tags" : [ ]
        }, {
          "url" : "http://sunsolve.sun.com/search/document.do?assetkey=1-26-228526-1",
          "name" : "228526",
          "refsource" : "SUNALERT",
          "tags" : [ ]
        }, {
          "url" : "http://support.avaya.com/elmodocs2/security/ASA-2006-205.htm",
          "name" : "http://support.avaya.com/elmodocs2/security/ASA-2006-205.htm",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2006/dsa-1044",
          "name" : "DSA-1044",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2006/dsa-1046",
          "name" : "DSA-1046",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2006/dsa-1051",
          "name" : "DSA-1051",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.gentoo.org/security/en/glsa/glsa-200604-12.xml",
          "name" : "GLSA-200604-12",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://www.gentoo.org/security/en/glsa/glsa-200604-18.xml",
          "name" : "GLSA-200604-18",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://www.gentoo.org/security/en/glsa/glsa-200605-09.xml",
          "name" : "GLSA-200605-09",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDKSA-2006:075",
          "name" : "MDKSA-2006:075",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDKSA-2006:076",
          "name" : "MDKSA-2006:076",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDKSA-2006:078",
          "name" : "MDKSA-2006:078",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.mozilla.org/security/announce/2006/mfsa2006-27.html",
          "name" : "http://www.mozilla.org/security/announce/2006/mfsa2006-27.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.novell.com/linux/security/advisories/2006_04_25.html",
          "name" : "SUSE-SA:2006:022",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2006-0329.html",
          "name" : "RHSA-2006:0329",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2006-0330.html",
          "name" : "RHSA-2006:0330",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/432103/100/0/threaded",
          "name" : "20060426 ZDI-06-011: Mozilla Firefox Table Rebuilding Code Execution Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/436296/100/0/threaded",
          "name" : "FLSA:189137-1",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/436338/100/0/threaded",
          "name" : "FLSA:189137-2",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/438730/100/0/threaded",
          "name" : "HPSBUX02122",
          "refsource" : "HP",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/446657/100/200/threaded",
          "name" : "SSRT061236",
          "refsource" : "HP",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/446658/100/200/threaded",
          "name" : "SSRT061181",
          "refsource" : "HP",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/17516",
          "name" : "17516",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/1356",
          "name" : "ADV-2006-1356",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/3391",
          "name" : "ADV-2006-3391",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/3748",
          "name" : "ADV-2006-3748",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/3749",
          "name" : "ADV-2006-3749",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2008/0083",
          "name" : "ADV-2008-0083",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.zerodayinitiative.com/advisories/ZDI-06-011/",
          "name" : "http://www.zerodayinitiative.com/advisories/ZDI-06-011/",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/25985",
          "name" : "mozilla-table-rebuilding-code-execution(25985)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11164",
          "name" : "oval:org.mitre.oval:def:11164",
          "refsource" : "OVAL",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1189",
          "name" : "oval:org.mitre.oval:def:1189",
          "refsource" : "OVAL",
          "tags" : [ ]
        }, {
          "url" : "https://usn.ubuntu.com/275-1/",
          "name" : "USN-275-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "https://usn.ubuntu.com/276-1/",
          "name" : "USN-276-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Mozilla Firefox and Thunderbird 1.x before 1.5.0.2 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0.1 allows remote attackers to execute arbitrary code via \"an invalid and non-sensical ordering of table-related tags\" that results in a negative array index."
        }, {
          "lang" : "en",
          "value" : "This vulnerability also affects Mozilla Suite before 1.7.13"
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.0.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.5:beta1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.5:beta2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:1.5.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:preview_release:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:seamonkey:1.0:*:alpha:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:seamonkey:1.0:beta:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:thunderbird:1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:thunderbird:1.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:thunderbird:1.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:thunderbird:1.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:thunderbird:1.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:thunderbird:1.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:thunderbird:1.0.5:beta:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:thunderbird:1.0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:thunderbird:1.0.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:thunderbird:1.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:thunderbird:1.5:beta2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:thunderbird:1.5.0.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2006-04-14T10:02Z",
    "lastModifiedDate" : "2018-10-19T15:46Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0749",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "mozilla",
            "product" : {
              "product_data" : [ {
                "product_name" : "firefox",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "mozilla_suite",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.7.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.7.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.7.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.7.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.7.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.7.12",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "seamonkey",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "thunderbird",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.7",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-399"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2006.26/SCOSA-2006.26.txt",
          "name" : "SCOSA-2006.26",
          "refsource" : "SCO",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "ftp://patches.sgi.com/support/free/security/advisories/20060404-01-U.asc",
          "name" : "20060404-01-U",
          "refsource" : "SGI",
          "tags" : [ "Broken Link" ]
        }, {
          "url" : "http://lists.suse.com/archive/suse-security-announce/2006-Apr/0003.html",
          "name" : "SUSE-SA:2006:021",
          "refsource" : "SUSE",
          "tags" : [ "Broken Link" ]
        }, {
          "url" : "http://secunia.com/advisories/19631",
          "name" : "19631",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/19696",
          "name" : "19696",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/19714",
          "name" : "19714",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/19721",
          "name" : "19721",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/19729",
          "name" : "19729",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/19746",
          "name" : "19746",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/19759",
          "name" : "19759",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/19780",
          "name" : "19780",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/19794",
          "name" : "19794",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/19811",
          "name" : "19811",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/19821",
          "name" : "19821",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/19823",
          "name" : "19823",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/19852",
          "name" : "19852",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/19862",
          "name" : "19862",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/19863",
          "name" : "19863",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/19902",
          "name" : "19902",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/19941",
          "name" : "19941",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/19950",
          "name" : "19950",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/20051",
          "name" : "20051",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/21033",
          "name" : "21033",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/21622",
          "name" : "21622",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/729",
          "name" : "729",
          "refsource" : "SREASON",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://sunsolve.sun.com/search/document.do?assetkey=1-26-102550-1",
          "name" : "102550",
          "refsource" : "SUNALERT",
          "tags" : [ "Broken Link" ]
        }, {
          "url" : "http://sunsolve.sun.com/search/document.do?assetkey=1-26-228526-1",
          "name" : "228526",
          "refsource" : "SUNALERT",
          "tags" : [ "Broken Link" ]
        }, {
          "url" : "http://support.avaya.com/elmodocs2/security/ASA-2006-205.htm",
          "name" : "http://support.avaya.com/elmodocs2/security/ASA-2006-205.htm",
          "refsource" : "CONFIRM",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.debian.org/security/2006/dsa-1044",
          "name" : "DSA-1044",
          "refsource" : "DEBIAN",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.debian.org/security/2006/dsa-1046",
          "name" : "DSA-1046",
          "refsource" : "DEBIAN",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.debian.org/security/2006/dsa-1051",
          "name" : "DSA-1051",
          "refsource" : "DEBIAN",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.gentoo.org/security/en/glsa/glsa-200604-12.xml",
          "name" : "GLSA-200604-12",
          "refsource" : "GENTOO",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.gentoo.org/security/en/glsa/glsa-200604-18.xml",
          "name" : "GLSA-200604-18",
          "refsource" : "GENTOO",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.gentoo.org/security/en/glsa/glsa-200605-09.xml",
          "name" : "GLSA-200605-09",
          "refsource" : "GENTOO",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/736934",
          "name" : "VU#736934",
          "refsource" : "CERT-VN",
          "tags" : [ "Third Party Advisory", "US Government Resource" ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDKSA-2006:075",
          "name" : "MDKSA-2006:075",
          "refsource" : "MANDRIVA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDKSA-2006:076",
          "name" : "MDKSA-2006:076",
          "refsource" : "MANDRIVA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDKSA-2006:078",
          "name" : "MDKSA-2006:078",
          "refsource" : "MANDRIVA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.mozilla.org/security/announce/2006/mfsa2006-18.html",
          "name" : "http://www.mozilla.org/security/announce/2006/mfsa2006-18.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.novell.com/linux/security/advisories/2006_04_25.html",
          "name" : "SUSE-SA:2006:022",
          "refsource" : "SUSE",
          "tags" : [ "Broken Link" ]
        }, {
          "url" : "http://www.redhat.com/archives/fedora-announce-list/2006-April/msg00153.html",
          "name" : "FEDORA-2006-410",
          "refsource" : "FEDORA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.redhat.com/archives/fedora-announce-list/2006-April/msg00154.html",
          "name" : "FEDORA-2006-411",
          "refsource" : "FEDORA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2006-0328.html",
          "name" : "RHSA-2006:0328",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2006-0329.html",
          "name" : "RHSA-2006:0329",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2006-0330.html",
          "name" : "RHSA-2006:0330",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/431126/100/0/threaded",
          "name" : "20060417 ZDI-06-009: Mozilla Firefox Tag Parsing Code Execution Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/434524/100/0/threaded",
          "name" : "SSRT061145",
          "refsource" : "HP",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/436296/100/0/threaded",
          "name" : "FLSA:189137-1",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/436338/100/0/threaded",
          "name" : "FLSA:189137-2",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/438730/100/0/threaded",
          "name" : "HPSBUX02122",
          "refsource" : "HP",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/17516",
          "name" : "17516",
          "refsource" : "BID",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA06-107A.html",
          "name" : "TA06-107A",
          "refsource" : "CERT",
          "tags" : [ "Third Party Advisory", "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/1356",
          "name" : "ADV-2006-1356",
          "refsource" : "VUPEN",
          "tags" : [ "Permissions Required", "Third Party Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/3391",
          "name" : "ADV-2006-3391",
          "refsource" : "VUPEN",
          "tags" : [ "Permissions Required", "Third Party Advisory" ]
        }, {
          "url" : "http://www.zerodayinitiative.com/advisories/ZDI-06-009.html",
          "name" : "http://www.zerodayinitiative.com/advisories/ZDI-06-009.html",
          "refsource" : "MISC",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/25819",
          "name" : "mozilla-nshtmlcontentsink-memory-corruption(25819)",
          "refsource" : "XF",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11704",
          "name" : "oval:org.mitre.oval:def:11704",
          "refsource" : "OVAL",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1848",
          "name" : "oval:org.mitre.oval:def:1848",
          "refsource" : "OVAL",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "https://usn.ubuntu.com/271-1/",
          "name" : "USN-271-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "https://usn.ubuntu.com/275-1/",
          "name" : "USN-275-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "https://usn.ubuntu.com/276-1/",
          "name" : "USN-276-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "nsHTMLContentSink.cpp in Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown vectors involving a \"particular sequence of HTML tags\" that leads to memory corruption."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "1.0",
          "versionEndIncluding" : "1.5"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:mozilla_suite:*:*:*:*:*:*:*:*",
          "versionEndExcluding" : "1.7.13"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:seamonkey:*:*:*:*:*:*:*:*",
          "versionEndExcluding" : "1.0"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "1.0",
          "versionEndExcluding" : "1.0.8"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2006-04-14T10:02Z",
    "lastModifiedDate" : "2018-10-19T15:46Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0750",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "supersmashbrothers",
            "product" : {
              "product_data" : [ {
                "product_name" : "army_system",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.1.0_for_ipb",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secubox.shadock.net/Invision_Power_Board_Army_System_Mod_2.1_and_prior_SQL_Injection_Exploit.html",
          "name" : "http://secubox.shadock.net/Invision_Power_Board_Army_System_Mod_2.1_and_prior_SQL_Injection_Exploit.html",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18840",
          "name" : "18840",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/424846/100/0/threaded",
          "name" : "20060212 Invision Power Board Army System Mod <= 2.1 SQL Injection Exploit",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16606",
          "name" : "16606",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0561",
          "name" : "ADV-2006-0561",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24654",
          "name" : "ipb-armysystem-sql-injection(24654)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in army.php in supersmashbrothers (SSB) Army System 2.1.0 for Invision Power Board (IPB) allows remote attackers to execute arbitrary SQL commands via the userstat parameter in an army action to index.php."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:supersmashbrothers:army_system:2.1.0_for_ipb:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-18T02:02Z",
    "lastModifiedDate" : "2018-10-19T15:46Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0751",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "noofs_team",
            "product" : {
              "product_data" : [ {
                "product_name" : "network_object_oriented_file_system",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://archives.neohapsis.com/archives/apps/freshmeat/2006-02/0003.html",
          "name" : "[fm-news] 20060204 Newsletter for Friday, February 03rd 2006",
          "refsource" : "MLIST",
          "tags" : [ ]
        }, {
          "url" : "http://freshmeat.net/projects/noofs/?branch_id=60557&release_id=218852",
          "name" : "http://freshmeat.net/projects/noofs/?branch_id=60557&release_id=218852",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/23052",
          "name" : "23052",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/23053",
          "name" : "23053",
          "refsource" : "OSVDB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple unspecified vulnerabilities in the (1) Filesystem in USErspace (FUSE) client and (2) NOOFS daemon in in Network Object Oriented File System (NOOFS) before 0.9.0 have unspecified impact and attack vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:noofs_team:network_object_oriented_file_system:0.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:noofs_team:network_object_oriented_file_system:0.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:noofs_team:network_object_oriented_file_system:0.8.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "acInsufInfo" : true,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-18T02:02Z",
    "lastModifiedDate" : "2011-03-08T02:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0752",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "niels_provos",
            "product" : {
              "product_data" : [ {
                "product_name" : "honeyd",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.6a",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.7a",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8a",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8b",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5a",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18867",
          "name" : "18867",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.honeyd.org/adv.2006-01",
          "name" : "http://www.honeyd.org/adv.2006-01",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.honeyd.org/phpBB2/viewtopic.php?t=106",
          "name" : "http://www.honeyd.org/phpBB2/viewtopic.php?t=106",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/425112/100/0/threaded",
          "name" : "20060212 honeyd security advisory: remote detection",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16595",
          "name" : "16595",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0552",
          "name" : "ADV-2006-0552",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24728",
          "name" : "honeyd-ipfrag-obtain-information(24728)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Niels Provos Honeyd before 1.5 replies to certain illegal IP packet fragments that other IP stack implementations would drop, which allows remote attackers to identify IP addresses that are being simulated using honeyd."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:niels_provos:honeyd:0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:niels_provos:honeyd:0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:niels_provos:honeyd:0.6a:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:niels_provos:honeyd:0.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:niels_provos:honeyd:0.7a:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:niels_provos:honeyd:0.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:niels_provos:honeyd:0.8a:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:niels_provos:honeyd:0.8b:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:niels_provos:honeyd:1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:niels_provos:honeyd:1.5a:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-18T02:02Z",
    "lastModifiedDate" : "2018-10-19T15:46Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0753",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "ie",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.osvdb.org/23307",
          "name" : "23307",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/424959/100/0/threaded",
          "name" : "20060214 memory leak in IE?",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24846",
          "name" : "ie-windowstatus-dos(24846)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Memory leak in Microsoft Internet Explorer 6 for Windows XP Service Pack 2 allows remote attackers to cause a denial of service (memory consumption) via JavaScript that uses setInterval to repeatedly call a function to set the value of window.status."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:ie:6:windows_xp_sp2:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:H/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "HIGH",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 2.6
        },
        "severity" : "LOW",
        "exploitabilityScore" : 4.9,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2006-02-18T02:02Z",
    "lastModifiedDate" : "2018-10-19T15:46Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0754",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "dotproject",
            "product" : {
              "product_data" : [ {
                "product_name" : "dotproject",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18879",
          "name" : "18879",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/23206",
          "name" : "23206",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/424957/100/0/threaded",
          "name" : "20060214 dotproject <= 2.0.1 remote code execution",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/425285/100/0/threaded",
          "name" : "20060215 Re: dotproject <= 2.0.1 remote code execution",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16648",
          "name" : "16648",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0604",
          "name" : "ADV-2006-0604",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24745",
          "name" : "dotproject-phpinfo-check-obtain-info(24745)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "** DISPUTED ** dotProject 2.0.1 and earlier allows remote attackers to obtain sensitive information via direct requests with an invalid baseDir to certain PHP scripts in the db directory, which reveal the path in an error message.  NOTE: the vendor disputes this issue, saying that it could only occur if the administrator ignores the installation instructions as well as warnings generated by check.php."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:dotproject:dotproject:2.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:dotproject:dotproject:2.0.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-18T02:02Z",
    "lastModifiedDate" : "2018-10-19T15:46Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0755",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "dotproject",
            "product" : {
              "product_data" : [ {
                "product_name" : "dotproject",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18879",
          "name" : "18879",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/23209",
          "name" : "23209",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/23210",
          "name" : "23210",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/23211",
          "name" : "23211",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/23212",
          "name" : "23212",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/23213",
          "name" : "23213",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/23214",
          "name" : "23214",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/23215",
          "name" : "23215",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/23216",
          "name" : "23216",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/23217",
          "name" : "23217",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/23218",
          "name" : "23218",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/23219",
          "name" : "23219",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/424957/100/0/threaded",
          "name" : "20060214 dotproject <= 2.0.1 remote code execution",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/425285/100/0/threaded",
          "name" : "20060215 Re: dotproject <= 2.0.1 remote code execution",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16648",
          "name" : "16648",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0604",
          "name" : "ADV-2006-0604",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24738",
          "name" : "dotproject-multiple-basedir-file-include(24738)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "** DISPUTED ** Multiple PHP remote file include vulnerabilities in dotProject 2.0.1 and earlier, when register_globals is enabled, allow remote attackers to execute arbitrary commands via the baseDir parameter in (1) db_adodb.php, (2) db_connect.php, (3) session.php, (4) vw_usr_roles.php, (5) calendar.php, (6) date_format.php, and (7) tasks/gantt.php; and the dPconfig[root_dir] parameter in (8) projects/gantt.php, (9) gantt2.php, and (10) vw_files.php.  NOTE: the vendor disputes this issue, stating that the product documentation clearly recommends that the system administrator disable register_globals, and that the check.php script warns against this setting.  Also, the vendor says that the protection.php/siteurl vector is incorrect because protection.php does not exist in the product."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:dotproject:dotproject:2.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:dotproject:dotproject:2.0.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:H/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "HIGH",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.1
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 4.9,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-18T02:02Z",
    "lastModifiedDate" : "2018-10-19T15:46Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0756",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "dotproject",
            "product" : {
              "product_data" : [ {
                "product_name" : "dotproject",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18879",
          "name" : "18879",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/434",
          "name" : "434",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/23207",
          "name" : "23207",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/23208",
          "name" : "23208",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/424957/100/0/threaded",
          "name" : "20060214 dotproject <= 2.0.1 remote code execution",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/425285/100/0/threaded",
          "name" : "20060215 Re: dotproject <= 2.0.1 remote code execution",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16648",
          "name" : "16648",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0604",
          "name" : "ADV-2006-0604",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24745",
          "name" : "dotproject-phpinfo-check-obtain-info(24745)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "** DISPUTED ** dotProject 2.0.1 and earlier leaves (1) phpinfo.php and (2) check.php accessible under the /docs/ directory after installation, which allows remote attackers to obtain sensitive configuration information.  NOTE: the vendor disputes this issue, saying that it could only occur if the administrator ignores the installation instructions as well as warnings generated by check.php."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:dotproject:dotproject:2.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:dotproject:dotproject:2.0.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-18T02:02Z",
    "lastModifiedDate" : "2018-10-19T15:46Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0757",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "hivemail",
            "product" : {
              "product_data" : [ {
                "product_name" : "hivemail",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.1_beta1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.1_rc",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2_sp1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3_beta1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3_rc1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://archives.neohapsis.com/archives/bugtraq/2006-02/0162.html",
          "name" : "20060210 HiveMail <= 1.3 Multiple Vulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://forum.hivemail.com/showthread.php?p=26745",
          "name" : "http://forum.hivemail.com/showthread.php?p=26745",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18807",
          "name" : "18807",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.gulftech.org/?node=research&article_id=00098-02102006",
          "name" : "http://www.gulftech.org/?node=research&article_id=00098-02102006",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16591",
          "name" : "16591",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0527",
          "name" : "ADV-2006-0527",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24618",
          "name" : "hivemail-multiple-file-include(24618)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple eval injection vulnerabilities in HiveMail 1.3 and earlier allow remote attackers to execute arbitrary PHP code via (1) the contactgroupid parameter in addressbook.update.php, (2) the messageid parameter in addressbook.add.php, (3) the folderid parameter in folders.update.php, and possibly certain parameters in (4) calendar.event.php, (5) index.php, (6) pop.download.php, (7) read.bounce.php, (8) rules.block.php, (9) language.php, and (10) certain other scripts, as demonstrated by an addressbook.update.php request with a contactgroupid value of phpinfo() preceded by facilitators."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hivemail:hivemail:1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hivemail:hivemail:1.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hivemail:hivemail:1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hivemail:hivemail:1.2.1_beta1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hivemail:hivemail:1.2.1_rc:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hivemail:hivemail:1.2.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hivemail:hivemail:1.2_sp1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hivemail:hivemail:1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hivemail:hivemail:1.3_beta1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hivemail:hivemail:1.3_rc1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-18T02:02Z",
    "lastModifiedDate" : "2017-07-20T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0758",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "hivemail",
            "product" : {
              "product_data" : [ {
                "product_name" : "hivemail",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.1_beta1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.1_rc",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2_sp1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3_beta1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3_rc1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://archives.neohapsis.com/archives/bugtraq/2006-02/0162.html",
          "name" : "20060210 HiveMail <= 1.3 Multiple Vulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://forum.hivemail.com/showthread.php?p=26745",
          "name" : "http://forum.hivemail.com/showthread.php?p=26745",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18807",
          "name" : "18807",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.gulftech.org/?node=research&article_id=00098-02102006",
          "name" : "http://www.gulftech.org/?node=research&article_id=00098-02102006",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16591",
          "name" : "16591",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0527",
          "name" : "ADV-2006-0527",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24622",
          "name" : "hivemail-index-xss(24622)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple cross-site scripting (XSS) vulnerabilities in HiveMail 1.3 and earlier allow remote attackers to inject arbitrary web script or HTML via a URL encoded expression in the query string in (1) index.php and (2) possibly certain other scripts, which is not properly cleansed when accessed from the $_SERVER['PHP_SELF'] variable."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hivemail:hivemail:1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hivemail:hivemail:1.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hivemail:hivemail:1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hivemail:hivemail:1.2.1_beta1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hivemail:hivemail:1.2.1_rc:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hivemail:hivemail:1.2.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hivemail:hivemail:1.2_sp1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hivemail:hivemail:1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hivemail:hivemail:1.3_beta1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hivemail:hivemail:1.3_rc1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-18T02:02Z",
    "lastModifiedDate" : "2017-07-20T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0759",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "hivemail",
            "product" : {
              "product_data" : [ {
                "product_name" : "hivemail",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.1_beta1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.1_rc",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2_sp1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3_beta1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3_rc1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://archives.neohapsis.com/archives/bugtraq/2006-02/0162.html",
          "name" : "20060210 HiveMail <= 1.3 Multiple Vulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://forum.hivemail.com/showthread.php?p=26745",
          "name" : "http://forum.hivemail.com/showthread.php?p=26745",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18807",
          "name" : "18807",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/422",
          "name" : "422",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.gulftech.org/?node=research&article_id=00098-02102006",
          "name" : "http://www.gulftech.org/?node=research&article_id=00098-02102006",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16591",
          "name" : "16591",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0527",
          "name" : "ADV-2006-0527",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24623",
          "name" : "hivemail-index-sql-injection(24623)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple SQL injection vulnerabilities in HiveMail 1.3 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the contactgroupid parameter in addressbook.update.php, (2) the messageid parameter in addressbook.add.php, (3) the folderid parameter in folders.update.php, and possibly certain parameters in (4) calendar.event.php, (5) index.php, (6) pop.download.php, (7) read.bounce.php, (8) rules.block.php, (9) language.php, and (10) certain other scripts; and allow remote authenticated users to execute arbitrary SQL commands via (11) the folderid parameter in index.php and (12) possibly other parameters in certain other scripts, because $_SERVER['PHP_SELF'] is improperly handled."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hivemail:hivemail:1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hivemail:hivemail:1.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hivemail:hivemail:1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hivemail:hivemail:1.2.1_beta1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hivemail:hivemail:1.2.1_rc:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hivemail:hivemail:1.2.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hivemail:hivemail:1.2_sp1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hivemail:hivemail:1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hivemail:hivemail:1.3_beta1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hivemail:hivemail:1.3_rc1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-18T02:02Z",
    "lastModifiedDate" : "2017-07-20T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0760",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "lighttpd",
            "product" : {
              "product_data" : [ {
                "product_name" : "lighttpd",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.16",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.8",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lighttpd.net/news/",
          "name" : "http://www.lighttpd.net/news/",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18869",
          "name" : "18869",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.lighttpd.net/news/",
          "name" : "http://lighttpd.net/news/",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/23229",
          "name" : "23229",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0550",
          "name" : "ADV-2006-0550",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24699",
          "name" : "lighttpd-ext-source-disclosure(24699)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "LightTPD 1.4.8 and earlier, when the web root is on a case-insensitive filesystem, allows remote attackers to bypass URL checks and obtain sensitive information via file extensions with unexpected capitalization, as demonstrated by a request for index.PHP when the configuration invokes the PHP interpreter only for \".php\" names."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:lighttpd:lighttpd:1.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:lighttpd:lighttpd:1.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:lighttpd:lighttpd:1.1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:lighttpd:lighttpd:1.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:lighttpd:lighttpd:1.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:lighttpd:lighttpd:1.1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:lighttpd:lighttpd:1.1.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:lighttpd:lighttpd:1.1.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:lighttpd:lighttpd:1.1.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:lighttpd:lighttpd:1.1.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:lighttpd:lighttpd:1.1.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:lighttpd:lighttpd:1.1.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:lighttpd:lighttpd:1.2.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:lighttpd:lighttpd:1.2.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:lighttpd:lighttpd:1.2.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:lighttpd:lighttpd:1.2.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:lighttpd:lighttpd:1.2.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:lighttpd:lighttpd:1.2.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:lighttpd:lighttpd:1.2.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:lighttpd:lighttpd:1.2.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:lighttpd:lighttpd:1.2.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:lighttpd:lighttpd:1.3.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:lighttpd:lighttpd:1.3.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:lighttpd:lighttpd:1.3.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:lighttpd:lighttpd:1.3.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:lighttpd:lighttpd:1.3.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:lighttpd:lighttpd:1.3.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:lighttpd:lighttpd:1.3.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:lighttpd:lighttpd:1.3.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:lighttpd:lighttpd:1.3.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:lighttpd:lighttpd:1.3.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:lighttpd:lighttpd:1.3.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:lighttpd:lighttpd:1.3.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:lighttpd:lighttpd:1.3.12:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:lighttpd:lighttpd:1.3.13:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:lighttpd:lighttpd:1.3.14:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:lighttpd:lighttpd:1.3.15:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:lighttpd:lighttpd:1.3.16:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:lighttpd:lighttpd:1.4.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:lighttpd:lighttpd:1.4.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:lighttpd:lighttpd:1.4.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:lighttpd:lighttpd:1.4.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:lighttpd:lighttpd:1.4.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:lighttpd:lighttpd:1.4.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:lighttpd:lighttpd:1.4.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:lighttpd:lighttpd:1.4.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:lighttpd:lighttpd:1.4.8:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:H/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "HIGH",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 2.6
        },
        "severity" : "LOW",
        "exploitabilityScore" : 4.9,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-18T02:02Z",
    "lastModifiedDate" : "2017-07-20T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0761",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "rim",
            "product" : {
              "product_data" : [ {
                "product_name" : "blackberry_enterprise_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2_sp2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2_sp2a",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2_sp3a",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2_sp4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2_sp4_hotfix2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.6.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.6_sp1a",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.6_sp4_hotfix2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0_sp1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0_sp2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0_sp3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.blackberry.com/knowledgecenterpublic/livelink.exe/fetch/2000/8021/8149/8052/Support_-_Corrupt_Word_file_may_cause_buffer_overflow_in_the_BlackBerry_Attachment_Service.html?nodeid=1181753&vernum=2",
          "name" : "http://www.blackberry.com/knowledgecenterpublic/livelink.exe/fetch/2000/8021/8149/8052/Support_-_Corrupt_Word_file_may_cause_buffer_overflow_in_the_BlackBerry_Attachment_Service.html?nodeid=1181753&vernum=2",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/424728/100/0/threaded",
          "name" : "20060210 Corrupt Word file may cause buffer overflow in the Blackberry Attachment Service",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16590",
          "name" : "16590",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0530",
          "name" : "ADV-2006-0530",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24629",
          "name" : "blackberry-attachment-word-bo(24629)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Buffer overflow in BlackBerry Attachment Service in Research in Motion (RIM) BlackBerry Enterprise Server 2.2 and 4.0 before SP3 Hotfix 4 for IBM Lotus Domino, 3.6 before SP7 and 5.0 before SP3 Hotfix 3 for Microsoft Exchangem, and 4.0 for Novell GroupWise before SP3 Hotfix 1 might allow user-assisted remote attackers to execute arbitrary code on the server via a crafted Microsoft Word document that is opened on a wireless device."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rim:blackberry_enterprise_server:2.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rim:blackberry_enterprise_server:2.2_sp2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rim:blackberry_enterprise_server:2.2_sp2a:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rim:blackberry_enterprise_server:2.2_sp3a:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rim:blackberry_enterprise_server:2.2_sp4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rim:blackberry_enterprise_server:2.2_sp4_hotfix2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rim:blackberry_enterprise_server:3.6:*:exchange:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rim:blackberry_enterprise_server:3.6.1:*:exchange:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rim:blackberry_enterprise_server:3.6_sp1a:*:exchange:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rim:blackberry_enterprise_server:3.6_sp4_hotfix2:*:exchange:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rim:blackberry_enterprise_server:4.0:*:domino:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rim:blackberry_enterprise_server:4.0:*:novell_groupwise:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rim:blackberry_enterprise_server:4.0_sp1:*:domino:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rim:blackberry_enterprise_server:4.0_sp1:*:novell_groupwise:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rim:blackberry_enterprise_server:4.0_sp2:*:domino:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rim:blackberry_enterprise_server:4.0_sp2:*:novell_groupwise:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rim:blackberry_enterprise_server:4.0_sp3:*:domino:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rim:blackberry_enterprise_server:4.0_sp3:*:novell_groupwise:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:H/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "HIGH",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.1
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 4.9,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2006-02-18T02:02Z",
    "lastModifiedDate" : "2018-10-19T15:46Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0762",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "winability",
            "product" : {
              "product_data" : [ {
                "product_name" : "folder_guard",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.11",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/archive/1/424855/100/0/threaded",
          "name" : "20060213 Folder Guard password protection bypass",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/424905/100/0/threaded",
          "name" : "20060213 Re: Folder Guard password protection bypass",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24725",
          "name" : "folderguard-fguard-bypass-authentication(24725)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "WinAbility Folder Guard 4.11 allows local users to gain unauthorized access to certain capabilities of the application by renaming or moving the password file (FGuard.FGP), which disables the password requirement."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:winability:folder_guard:4.11:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 4.6
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 3.9,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-18T02:02Z",
    "lastModifiedDate" : "2018-10-19T15:46Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0763",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "cpanel",
            "product" : {
              "product_data" : [ {
                "product_name" : "cpanel",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://archives.neohapsis.com/archives/fulldisclosure/2006-02/0129.html",
          "name" : "20060207 Re: cPanel Multiple Cross Site Scripting Vulnerability",
          "refsource" : "FULLDISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/22971",
          "name" : "22971",
          "refsource" : "OSVDB",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24839",
          "name" : "cpanel-dowebmailforward-xss(24839)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in dowebmailforward.cgi in cPanel allows remote attackers to inject arbitrary web script or HTML via a URL encoded value in the fwd parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cpanel:cpanel:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-18T02:02Z",
    "lastModifiedDate" : "2017-07-20T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0764",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "cisco",
            "product" : {
              "product_data" : [ {
                "product_name" : "anomaly_guard_module",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.0(1)",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0(3)",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "guard",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.0(1)",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0(3)",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "traffic_anomaly_detector_module",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.0(1)",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0(3)",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18904",
          "name" : "18904",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/435",
          "name" : "435",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1015637",
          "name" : "1015637",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1015638",
          "name" : "1015638",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.cisco.com/en/US/products/products_security_advisory09186a008060519a.shtml",
          "name" : "20060215 TACACS+ Authentication Bypass in Cisco Anomaly Detection and Mitigation Products",
          "refsource" : "CISCO",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/23237",
          "name" : "23237",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16661",
          "name" : "16661",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0612",
          "name" : "ADV-2006-0612",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24689",
          "name" : "cisco-tacacs-auth-bypass(24689)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The Authentication, Authorization, and Accounting (AAA) capability in versions 5.0(1) and 5.0(3) of the software used by multiple Cisco Anomaly Detection and Mitigation products, when running with an incomplete TACACS+ configuration without a \"tacacs-server host\" command, allows remote attackers to bypass authentication and gain privileges, aka Bug ID CSCsd21455."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:anomaly_guard_module:5.0\\(1\\):*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:anomaly_guard_module:5.0\\(3\\):*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:guard:5.0\\(1\\):*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:guard:5.0\\(3\\):*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:traffic_anomaly_detector_module:5.0\\(1\\):*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:cisco:traffic_anomaly_detector_module:5.0\\(3\\):*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:H/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "HIGH",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.1
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 4.9,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-18T02:02Z",
    "lastModifiedDate" : "2017-07-20T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0765",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "mirabilis",
            "product" : {
              "product_data" : [ {
                "product_name" : "icq",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2003a",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2003b",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "icq_lite",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/archive/1/425078/100/0/threaded",
          "name" : "20060215 Mirabiliz ICQ 2002/2003/ LITE 4.0/4.1 LONG (DIRECTORY + FILENAME) EXPLOIT",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16655",
          "name" : "16655",
          "refsource" : "BID",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "GUI display truncation vulnerability in ICQ Inc. (formerly Mirabilis) ICQ 2003a, 2003b, Lite 4.0, Lite 4.1, and possibly other Windows versions allows user-assisted remote attackers to hide malicious file extensions, bypass Windows security warnings via a filename that is all uppercase and of a specific length, which truncates the malicious extension from the display and could trick a user into executing arbitrary programs."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mirabilis:icq:2003a:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mirabilis:icq:2003b:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mirabilis:icq_lite:4.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mirabilis:icq_lite:4.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:H/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "HIGH",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.1
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 4.9,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2006-02-18T02:02Z",
    "lastModifiedDate" : "2018-10-19T15:46Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0766",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "mirabilis",
            "product" : {
              "product_data" : [ {
                "product_name" : "icq",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2003a",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2003b",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "icq_lite",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/archive/1/425078/100/0/threaded",
          "name" : "20060215 Mirabiliz ICQ 2002/2003/ LITE 4.0/4.1 LONG (DIRECTORY + FILENAME) EXPLOIT",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16655",
          "name" : "16655",
          "refsource" : "BID",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "ICQ Inc. (formerly Mirabilis) ICQ 2003a, 2003b, Lite 4.0, Lite 4.1, and possibly other Windows versions allows user-assisted remote attackers to hide malicious file extensions and bypass Windows security warnings via a filename that ends in an assumed-safe extension such as JPG, and possibly containing other modified properties such as company name, icon, and description, which could trick a user into executing arbitrary programs."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mirabilis:icq:2003a:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mirabilis:icq:2003b:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mirabilis:icq_lite:4.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mirabilis:icq_lite:4.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:H/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "HIGH",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.1
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 4.9,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2006-02-18T02:02Z",
    "lastModifiedDate" : "2018-10-19T15:46Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0767",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "nathan_neulinger",
            "product" : {
              "product_data" : [ {
                "product_name" : "cgiwrap",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.5_beta",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.6.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.6.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.6.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.6.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.6_beta1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.6_beta2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.6_beta3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.6_beta4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.6_beta5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.6_beta6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.6_beta7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.6_beta8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.8_rc1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.21",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.22",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.23",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.24",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18797",
          "name" : "18797",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://sourceforge.net/project/showfiles.php?group_id=8209",
          "name" : "http://sourceforge.net/project/showfiles.php?group_id=8209",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://sourceforge.net/project/shownotes.php?release_id=393274&group_id=8209",
          "name" : "http://sourceforge.net/project/shownotes.php?release_id=393274&group_id=8209",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16669",
          "name" : "16669",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0601",
          "name" : "ADV-2006-0601",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24717",
          "name" : "cgiwrap-error-information-disclosure(24717)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "CGIWrap before 3.10 allows remote attackers to obtain sensitive information via unknown attack vectors that cause errors in scripts that reveal system information."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:nathan_neulinger:cgiwrap:3.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:nathan_neulinger:cgiwrap:3.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:nathan_neulinger:cgiwrap:3.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:nathan_neulinger:cgiwrap:3.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:nathan_neulinger:cgiwrap:3.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:nathan_neulinger:cgiwrap:3.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:nathan_neulinger:cgiwrap:3.5_beta:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:nathan_neulinger:cgiwrap:3.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:nathan_neulinger:cgiwrap:3.6.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:nathan_neulinger:cgiwrap:3.6.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:nathan_neulinger:cgiwrap:3.6.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:nathan_neulinger:cgiwrap:3.6.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:nathan_neulinger:cgiwrap:3.6_beta1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:nathan_neulinger:cgiwrap:3.6_beta2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:nathan_neulinger:cgiwrap:3.6_beta3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:nathan_neulinger:cgiwrap:3.6_beta4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:nathan_neulinger:cgiwrap:3.6_beta5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:nathan_neulinger:cgiwrap:3.6_beta6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:nathan_neulinger:cgiwrap:3.6_beta7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:nathan_neulinger:cgiwrap:3.6_beta8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:nathan_neulinger:cgiwrap:3.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:nathan_neulinger:cgiwrap:3.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:nathan_neulinger:cgiwrap:3.8_rc1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:nathan_neulinger:cgiwrap:3.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:nathan_neulinger:cgiwrap:3.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:nathan_neulinger:cgiwrap:3.21:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:nathan_neulinger:cgiwrap:3.22:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:nathan_neulinger:cgiwrap:3.23:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:nathan_neulinger:cgiwrap:3.24:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-18T21:02Z",
    "lastModifiedDate" : "2017-07-20T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0768",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "kadu",
            "product" : {
              "product_data" : [ {
                "product_name" : "kadu",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.4.3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://marc.info/?l=full-disclosure&m=114000770431441&w=2",
          "name" : "20060215 Kadu Remote Denial Of Service Fun",
          "refsource" : "FULLDISC",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18824",
          "name" : "18824",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.piotrbania.com/all/adv/kadu-fun.txt",
          "name" : "http://www.piotrbania.com/all/adv/kadu-fun.txt",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/425134/100/0/threaded",
          "name" : "20060215 Kadu Remote Denial Of Service Fun",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0609",
          "name" : "ADV-2006-0609",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24720",
          "name" : "kadu-image-request-dos(24720)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Kadu 0.4.3 allows remote attackers to cause a denial of service (application crash) via a large number of image send requests."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:kadu:kadu:0.4.3:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-18T21:02Z",
    "lastModifiedDate" : "2018-10-19T15:46Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0769",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "sun",
            "product" : {
              "product_data" : [ {
                "product_name" : "solaris",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18891",
          "name" : "18891",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1015635",
          "name" : "1015635",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://sunsolve.sun.com/search/document.do?assetkey=1-26-102186-1",
          "name" : "102186",
          "refsource" : "SUNALERT",
          "tags" : [ ]
        }, {
          "url" : "http://www.ciac.org/ciac/bulletins/q-126.shtml",
          "name" : "Q-126",
          "refsource" : "CIAC",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16658",
          "name" : "16658",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0608",
          "name" : "ADV-2006-0608",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24680",
          "name" : "solaris-kerberos-command-execution(24680)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1580",
          "name" : "oval:org.mitre.oval:def:1580",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in in.rexecd in Solaris 10 allows local users to gain privileges on Kerberos systems via unknown attack vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:sun:solaris:10.0:*:sparc:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.2
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 3.9,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-18T21:02Z",
    "lastModifiedDate" : "2017-10-11T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0770",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "mybulletinboard",
            "product" : {
              "product_data" : [ {
                "product_name" : "mybulletinboard",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0_final",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0_pr2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0_preview_release_2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0_rc2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0_rc4",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18866",
          "name" : "18866",
          "refsource" : "SECUNIA",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/23264",
          "name" : "23264",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0635",
          "name" : "ADV-2006-0635",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24748",
          "name" : "mybb-advanceddetails-xss(24748)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in calendar.php in MyBulletinBoard (MyBB) 1.0.4 allows remote attackers to inject arbitrary web script or HTML via a URL that is not sanitized before being returned as a link in \"advanced details\".  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mybulletinboard:mybulletinboard:1.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mybulletinboard:mybulletinboard:1.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mybulletinboard:mybulletinboard:1.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mybulletinboard:mybulletinboard:1.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mybulletinboard:mybulletinboard:1.0_final:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mybulletinboard:mybulletinboard:1.0_pr2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mybulletinboard:mybulletinboard:1.0_preview_release_2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mybulletinboard:mybulletinboard:1.0_rc2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mybulletinboard:mybulletinboard:1.0_rc4:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:H/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "HIGH",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 2.6
        },
        "severity" : "LOW",
        "exploitabilityScore" : 4.9,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2006-02-18T21:02Z",
    "lastModifiedDate" : "2017-07-20T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0771",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "even_balance",
            "product" : {
              "product_data" : [ {
                "product_name" : "punkbuster",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.180",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-134"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://aluigi.altervista.org/adv/sof2pbfs-adv.txt",
          "name" : "http://aluigi.altervista.org/adv/sof2pbfs-adv.txt",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://archives.neohapsis.com/archives/fulldisclosure/2006-02/0372.html",
          "name" : "20060216 Soldier of Fortune II format string through PunkBuster 1.180",
          "refsource" : "FULLDISC",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18917",
          "name" : "18917",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/448",
          "name" : "448",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/425286/100/0/threaded",
          "name" : "20060216 Soldier of Fortune II format string through PunkBuster 1.180",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16703",
          "name" : "16703",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24792",
          "name" : "punkbuster-cvars-format-string(24792)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Format string vulnerability in PunkBuster 1.180 and earlier, as used by Soldier of Fortune II and possibly other games, allows remote attackers to cause a denial of service (server crash) and possibly execute arbitrary code via format string specifiers in invalid cvar values, which are not properly handled when the server kicks the player and records the reason."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:even_balance:punkbuster:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.180"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.4
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-18T21:02Z",
    "lastModifiedDate" : "2018-10-19T15:46Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0772",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "hitachi",
            "product" : {
              "product_data" : [ {
                "product_name" : "business_logic",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "02_03",
                    "version_affected" : "="
                  }, {
                    "version_value" : "03_00",
                    "version_affected" : "="
                  }, {
                    "version_value" : "03_00_b",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18817",
          "name" : "18817",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.hitachi-support.com/security_e/vuls_e/HS06-002_e/index-e.html",
          "name" : "http://www.hitachi-support.com/security_e/vuls_e/HS06-002_e/index-e.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/23099",
          "name" : "23099",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16602",
          "name" : "16602",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0532",
          "name" : "ADV-2006-0532",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/23877",
          "name" : "hitachi-businesslogic-input-sql-injection(23877)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24621",
          "name" : "hitachi-businesslogic-recbox-sql-injection(24621)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in Hitachi Business Logic - Container 02-03 through 03-00-/B on Windows, and 03-00 through 03-00-/B on Linux, allows remote attackers to execute arbitrary SQL commands via unspecified vectors in the extended receiving box function."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hitachi:business_logic:02_03:*:windows:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hitachi:business_logic:03_00:*:linux:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hitachi:business_logic:*:*:linux:*:*:*:*:*",
          "versionEndIncluding" : "03_00_b"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hitachi:business_logic:*:*:windows:*:*:*:*:*",
          "versionEndIncluding" : "03_00_b"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-19T00:02Z",
    "lastModifiedDate" : "2017-07-20T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0773",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "hitachi",
            "product" : {
              "product_data" : [ {
                "product_name" : "business_logic",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "02_03",
                    "version_affected" : "="
                  }, {
                    "version_value" : "03_00",
                    "version_affected" : "="
                  }, {
                    "version_value" : "03_00_b",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18817",
          "name" : "18817",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.hitachi-support.com/security_e/vuls_e/HS06-002_e/index-e.html",
          "name" : "http://www.hitachi-support.com/security_e/vuls_e/HS06-002_e/index-e.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16602",
          "name" : "16602",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0532",
          "name" : "ADV-2006-0532",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24620",
          "name" : "hitachi-businesslogic-recbox-xss(24620)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in Hitachi Business Logic - Container 02-03 through 03-00-/B on Windows, and 03-00 through 03-00-/B on Linux, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors in the extended receiving box function."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hitachi:business_logic:02_03:*:windows:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hitachi:business_logic:03_00:*:linux:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hitachi:business_logic:*:*:linux:*:*:*:*:*",
          "versionEndIncluding" : "03_00_b"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hitachi:business_logic:*:*:windows:*:*:*:*:*",
          "versionEndIncluding" : "03_00_b"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-19T00:02Z",
    "lastModifiedDate" : "2017-07-20T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0774",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "lawrence_osiris",
            "product" : {
              "product_data" : [ {
                "product_name" : "db_esession",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0.2",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18805",
          "name" : "18805",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.gulftech.org/?node=research&article_id=00099-02112006",
          "name" : "http://www.gulftech.org/?node=research&article_id=00099-02112006",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/23104",
          "name" : "23104",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/424819/100/0/threaded",
          "name" : "20060211 DB_eSession deleteSession() SQL injection",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/433132/30/5160/threaded",
          "name" : "20060501 Re: DB_eSession deleteSession() SQL injection",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16598",
          "name" : "16598",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0528",
          "name" : "ADV-2006-0528",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24673",
          "name" : "dbesession-deletesession-sql-injection(24673)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in deleteSession() in DB_eSession library 1.0.2 and earlier, as used in multiple products, allows remote attackers to execute arbitrary SQL commands via the $_sess_id_set variable, which is usually derived from PHPSESSID."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:lawrence_osiris:db_esession:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.0.2"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-19T00:02Z",
    "lastModifiedDate" : "2018-10-19T15:46Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0775",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ridder_roeland",
            "product" : {
              "product_data" : [ {
                "product_name" : "birthsys",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://attrition.org/pipermail/vim/2006-February/000549.html",
          "name" : "20060215 EV0074 BirthSys 3.1 SQL injection (fwd)",
          "refsource" : "VIM",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18893",
          "name" : "18893",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/467",
          "name" : "467",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.evuln.com/vulns/74/summary.html",
          "name" : "http://www.evuln.com/vulns/74/summary.html",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/23185",
          "name" : "23185",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16684",
          "name" : "16684",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0621",
          "name" : "ADV-2006-0621",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24617",
          "name" : "birthsys-show-date-sql-injection(24617)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple SQL injection vulnerabilities in show.php in BirthSys 3.1 allow remote attackers to execute arbitrary SQL commands via the $month variable.  NOTE: a vector regarding the $date parameter and data.php (date.php) was originally reported, but this appears to be in error."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ridder_roeland:birthsys:3.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-19T00:02Z",
    "lastModifiedDate" : "2017-07-20T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0776",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "teca_scripts",
            "product" : {
              "product_data" : [ {
                "product_name" : "guestex",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18927",
          "name" : "18927",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/490",
          "name" : "490",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1015678",
          "name" : "1015678",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.evuln.com/vulns/77/summary.html",
          "name" : "http://www.evuln.com/vulns/77/summary.html",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/23182",
          "name" : "23182",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/426034/100/0/threaded",
          "name" : "20060224 [eVuln] Guestex XSS Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16711",
          "name" : "16711",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0640",
          "name" : "ADV-2006-0640",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24644",
          "name" : "guestex-script-xss(24644)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in guestex.pl in Teca Scripts Guestex 1.0 allows remote attackers to inject arbitrary web script or HTML via the url parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:teca_scripts:guestex:1.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-19T00:02Z",
    "lastModifiedDate" : "2018-10-19T15:46Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0777",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "teca_scripts",
            "product" : {
              "product_data" : [ {
                "product_name" : "guestex",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18927",
          "name" : "18927",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/489",
          "name" : "489",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.evuln.com/vulns/76/summary.html",
          "name" : "http://www.evuln.com/vulns/76/summary.html",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/23183",
          "name" : "23183",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/425970/100/0/threaded",
          "name" : "20060224 [eVuln] Guestex Shell Command Execution Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16711",
          "name" : "16711",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0640",
          "name" : "ADV-2006-0640",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24645",
          "name" : "guestex-script-execute-code(24645)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in guestex.pl in Teca Scripts Guestex 1.0 allows remote attackers to execute arbitrary shell commands via the email parameter, possibly involving shell metacharacters."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:teca_scripts:guestex:1.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-19T00:02Z",
    "lastModifiedDate" : "2018-10-19T15:46Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0778",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "xmb_forum",
            "product" : {
              "product_data" : [ {
                "product_name" : "xmb",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.9.3",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18821",
          "name" : "18821",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.gulftech.org/?node=research&article_id=00100-02122006",
          "name" : "http://www.gulftech.org/?node=research&article_id=00100-02122006",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/23117",
          "name" : "23117",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/23118",
          "name" : "23118",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/425084/100/0/threaded",
          "name" : "20060212 XMB Forums Multiple Vulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16604",
          "name" : "16604",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0529",
          "name" : "ADV-2006-0529",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.xmbforum.com/",
          "name" : "http://www.xmbforum.com/",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24646",
          "name" : "xmbforum-multiple-sql-injection(24646)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple SQL injection vulnerabilities in XMB Forums 1.9.3 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) $u2u_select array parameter to u2u.inc.php and (2) $val variable (fidpw0 cookie value) in today.php."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:xmb_forum:xmb:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.9.3"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-19T00:02Z",
    "lastModifiedDate" : "2018-10-18T16:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0779",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "xmb_forum",
            "product" : {
              "product_data" : [ {
                "product_name" : "xmb",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.9.3",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.gulftech.org/?node=research&article_id=00100-02122006",
          "name" : "http://www.gulftech.org/?node=research&article_id=00100-02122006",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/23119",
          "name" : "23119",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/425084/100/0/threaded",
          "name" : "20060212 XMB Forums Multiple Vulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16604",
          "name" : "16604",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0529",
          "name" : "ADV-2006-0529",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.xmbforum.com/",
          "name" : "http://www.xmbforum.com/",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24647",
          "name" : "xmbforum-u2u-xss(24647)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in u2u.php in XMB Forums 1.9.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the username parameter, as demonstrated using a URL-encoded iframe tag."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:xmb_forum:xmb:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.9.3"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-19T00:02Z",
    "lastModifiedDate" : "2018-10-18T16:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0780",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "perlblog",
            "product" : {
              "product_data" : [ {
                "product_name" : "perlblog",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.08",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.09",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.09b",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://evuln.com/vulns/81/summary.html",
          "name" : "http://evuln.com/vulns/81/summary.html",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18924",
          "name" : "18924",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/508",
          "name" : "508",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/426260/100/0/threaded",
          "name" : "20060227 [eVuln] PerlBlog Multiple Vulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16707",
          "name" : "16707",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24691",
          "name" : "perlblog-weblog-xss(24691)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple cross-site scripting (XSS) vulnerabilities in weblog.pl in PerlBlog 1.09b and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) name and (2) email parameters."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:perlblog:perlblog:1.08:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:perlblog:perlblog:1.09:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:perlblog:perlblog:1.09b:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-19T11:02Z",
    "lastModifiedDate" : "2018-10-18T16:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0781",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "perlblog",
            "product" : {
              "product_data" : [ {
                "product_name" : "perlblog",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.08",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.09",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.09b",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://evuln.com/vulns/81/summary.html",
          "name" : "http://evuln.com/vulns/81/summary.html",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18924",
          "name" : "18924",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/508",
          "name" : "508",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/426260/100/0/threaded",
          "name" : "20060227 [eVuln] PerlBlog Multiple Vulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16707",
          "name" : "16707",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24690",
          "name" : "perlblog-weblog-directory-traversal(24690)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Directory traversal vulnerability in weblog.pl in PerlBlog 1.09b and earlier allows remote attackers to read certain files via the month parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:perlblog:perlblog:1.08:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:perlblog:perlblog:1.09:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:perlblog:perlblog:1.09b:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-19T11:02Z",
    "lastModifiedDate" : "2018-10-18T16:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0782",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "perlblog",
            "product" : {
              "product_data" : [ {
                "product_name" : "perlblog",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.08",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.09",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.09b",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://evuln.com/vulns/81/summary.html",
          "name" : "http://evuln.com/vulns/81/summary.html",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18924",
          "name" : "18924",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/508",
          "name" : "508",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/426260/100/0/threaded",
          "name" : "20060227 [eVuln] PerlBlog Multiple Vulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16707",
          "name" : "16707",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24692",
          "name" : "perlblog-weblog-command-execution(24692)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in weblog.pl in PerlBlog 1.09b and earlier allows remote attackers to create arbitrary files and possibly execute arbitrary code via unspecified attack vectors related to improper handling of (1) the reply parameter, possibly involving injection of (2) the name parameter and (3) the body parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:perlblog:perlblog:1.08:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:perlblog:perlblog:1.09:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:perlblog:perlblog:1.09b:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-19T11:02Z",
    "lastModifiedDate" : "2018-10-18T16:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0783",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "siteframe",
            "product" : {
              "product_data" : [ {
                "product_name" : "siteframe_beaumont",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.1a",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18892",
          "name" : "18892",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/443",
          "name" : "443",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/23267",
          "name" : "23267",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/425180/100/0/threaded",
          "name" : "20060216 Siteframe Beaumont 5.0.2 <== User Comment Cross-Site Scripting Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16695",
          "name" : "16695",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24836",
          "name" : "siteframe-comment-xss(24836)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in page.php in in Siteframe Beaumont, possibly 5.0.2 or 5.0.1a, allows remote attackers to inject arbitrary web script or HTML via the comment_text parameter to the user comment page (/edit/Comment)."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:siteframe:siteframe_beaumont:5.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:siteframe:siteframe_beaumont:5.0.1a:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:siteframe:siteframe_beaumont:5.0.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-19T11:02Z",
    "lastModifiedDate" : "2018-10-18T16:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0784",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "d-link",
            "product" : {
              "product_data" : [ {
                "product_name" : "dwl-g700ap",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.00",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.01",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18932",
          "name" : "18932",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/441",
          "name" : "441",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/425169/100/0/threaded",
          "name" : "20060216 D-Link DWL-G700AP httpd DoS",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16690",
          "name" : "16690",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0637",
          "name" : "ADV-2006-0637",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24762",
          "name" : "dlink-admin-interface-dos(24762)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "D-Link DWL-G700AP with firmware 2.00 and 2.01 allows remote attackers to cause a denial of service (CAMEO HTTP service crash) via a request composed of \"GET\" followed by a space and two newlines, possibly triggering the crash due to missing arguments."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:d-link:dwl-g700ap:2.00:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:d-link:dwl-g700ap:2.01:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-19T11:02Z",
    "lastModifiedDate" : "2018-10-18T16:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0785",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "phpkit",
            "product" : {
              "product_data" : [ {
                "product_name" : "phpkit",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.6.1",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://retrogod.altervista.org/phpkit_161r2_incl_xpl.html",
          "name" : "http://retrogod.altervista.org/phpkit_161r2_incl_xpl.html",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://securitytracker.com/id?1015640",
          "name" : "1015640",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/425196/100/0/threaded",
          "name" : "20060216 PHPKIT >= 1.6.1r2 arbitrary local/remote inclusion (unproperly patched in previous versions)",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Absolute path traversal vulnerability in include.php in PHPKIT 1.6.1 Release 2 and earlier allows remote attackers to include and execute arbitrary local files via a direct request with a path parameter with a null character and beginning with (1) '/' (slash) for an absolute pathname or (2) a drive letter (such as \"C:\"), which bypasses checks for \"..\" sequences and trailing \".php\" extensions."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:phpkit:phpkit:*:rc2:*:*:*:*:*:*",
          "versionEndIncluding" : "1.6.1"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 6.4
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-19T11:02Z",
    "lastModifiedDate" : "2018-10-18T16:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0786",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "phpkit",
            "product" : {
              "product_data" : [ {
                "product_name" : "phpkit",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.6.1",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://retrogod.altervista.org/phpkit_161r2_incl_xpl.html",
          "name" : "http://retrogod.altervista.org/phpkit_161r2_incl_xpl.html",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://securityreason.com/securityalert/445",
          "name" : "445",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1015640",
          "name" : "1015640",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/425196/100/0/threaded",
          "name" : "20060216 PHPKIT >= 1.6.1r2 arbitrary local/remote inclusion (unproperly patched in previous versions)",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Incomplete blacklist vulnerability in include.php in PHPKIT 1.6.1 Release 2 and earlier, with allow_url_fopen enabled, allows remote attackers to conduct PHP remote file include attacks via a path parameter that specifies a (1) UNC share or (2) ftps URL, which bypasses the check for \"http://\", \"ftp://\", and \"https://\" URLs."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:phpkit:phpkit:*:rc2:*:*:*:*:*:*",
          "versionEndIncluding" : "1.6.1"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:H/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "HIGH",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.1
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 4.9,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-19T11:02Z",
    "lastModifiedDate" : "2018-10-18T16:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0787",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "plaino",
            "product" : {
              "product_data" : [ {
                "product_name" : "wimpy_mp3",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.2",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18900",
          "name" : "18900",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16696",
          "name" : "16696",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.xorcrew.net/xpa/XPA-WimpyMP3Player.txt",
          "name" : "http://www.xorcrew.net/xpa/XPA-WimpyMP3Player.txt",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24770",
          "name" : "wimpy-wimpytrackplays-no-auth(24770)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "wimpy_trackplays.php in Plaino Wimpy MP3 Player, possibly 5.2 and earlier, allows remote attackers to insert arbitrary strings into trackme.txt via the (1) trackFile, (2) trackArtist, and (3) trackTitle parameters, which can result in providing false information about songs, occupying excessive disk space with very long parameter values, and storing executable code that might be invoked through a different vulnerability.  NOTE: since this issue, as described by the original researcher, is entirely dependent on the presence of another vulnerability, it could be argued that Wimpy cannot be responsible for how its data file is processed by applications outside of its control. Since this issue might only be useful as a facilitator manipulation in another vulnerability, perhaps it should not be included in CVE."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:plaino:wimpy_mp3:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "5.2"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:H/Au:N/C:N/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "HIGH",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 4.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 4.9,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-19T11:02Z",
    "lastModifiedDate" : "2017-07-20T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0788",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "kyocera",
            "product" : {
              "product_data" : [ {
                "product_name" : "fs-3830n",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://archives.neohapsis.com/archives/fulldisclosure/2006-02/0344.html",
          "name" : "20060215 Kyocera Network Printers",
          "refsource" : "FULLDISC",
          "tags" : [ ]
        }, {
          "url" : "http://evader.wordpress.com/2006/02/16/kyocera-printers/",
          "name" : "http://evader.wordpress.com/2006/02/16/kyocera-printers/",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18896",
          "name" : "18896",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/23245",
          "name" : "23245",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16685",
          "name" : "16685",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0620",
          "name" : "ADV-2006-0620",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24772",
          "name" : "kyocera-fs3830n-no-auth(24772)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Kyocera 3830 (aka FS-3830N) printers have a back door that allows remote attackers to read and alter configuration settings via strings that begin with \"!R!SIOP0\", as demonstrated using (1) a connection to to TCP port 9100 or (2) the UNIX lp command."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:kyocera:fs-3830n:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-19T11:02Z",
    "lastModifiedDate" : "2017-07-20T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0789",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "kyocera",
            "product" : {
              "product_data" : [ {
                "product_name" : "fs-3830n",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://archives.neohapsis.com/archives/fulldisclosure/2006-02/0344.html",
          "name" : "20060215 Kyocera Network Printers",
          "refsource" : "FULLDISC",
          "tags" : [ ]
        }, {
          "url" : "http://evader.wordpress.com/2006/02/16/kyocera-printers/",
          "name" : "http://evader.wordpress.com/2006/02/16/kyocera-printers/",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18896",
          "name" : "18896",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/23246",
          "name" : "23246",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0620",
          "name" : "ADV-2006-0620",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24774",
          "name" : "kyocera-fs3830n-blank-password(24774)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Certain unspecified Kyocera printers have a default \"admin\" account with a blank password, which allows remote attackers to access an administrative menu via a telnet session."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:kyocera:fs-3830n:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-19T11:02Z",
    "lastModifiedDate" : "2017-07-20T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0790",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "rockliffe",
            "product" : {
              "product_data" : [ {
                "product_name" : "mailsite",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.2.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.3.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.22",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.31",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.immunitysec.com/pipermail/dailydave/2006-February/002926.html",
          "name" : "[Dailydave] 20060214 MailSite (WorldMail) fun",
          "refsource" : "MLIST",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18888",
          "name" : "18888",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16675",
          "name" : "16675",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0598",
          "name" : "ADV-2006-0598",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24686",
          "name" : "mailsite-ldap-dos(24686)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Rockliffe MailSite 7.0 and earlier allows remote attackers to cause a denial of service by sending crafted LDAP packets to port 389/TCP, as demonstrated by the ProtoVer LDAP testsuite."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rockliffe:mailsite:4.2.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rockliffe:mailsite:5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rockliffe:mailsite:5.3.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rockliffe:mailsite:6.1.22:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rockliffe:mailsite:7.0.31:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-19T21:02Z",
    "lastModifiedDate" : "2017-07-20T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0791",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "dreamcost",
            "product" : {
              "product_data" : [ {
                "product_name" : "hostadmin",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://archives.neohapsis.com/archives/fulldisclosure/2006-02/0340.html",
          "name" : "20060215 HostAdmin - Remote Command Execution Vulnerability",
          "refsource" : "FULLDISC",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18901",
          "name" : "18901",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1016273",
          "name" : "1016273",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/23241",
          "name" : "23241",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/435993/30/4650/threaded",
          "name" : "20060605 [MajorSecurity #9]HostAdmin <= 3.1 - Remote File Include Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/497093/100/0/threaded",
          "name" : "20081007 HostAdmin 3.* Remote File Include Vulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/497133/100/0/threaded",
          "name" : "20081007 Re: HostAdmin 3.* Remote File Include Vulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16682",
          "name" : "16682",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0618",
          "name" : "ADV-2006-0618",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.xorcrew.net/xpa/XPA-HostAdmin.txt",
          "name" : "http://www.xorcrew.net/xpa/XPA-HostAdmin.txt",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24723",
          "name" : "hostadmin-path-file-include(24723)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "PHP remote file inclusion vulnerability in index.php in DreamCost HostAdmin allows remote attackers to include arbitrary files via the $path variable, which is not initialized before use."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:dreamcost:hostadmin:3.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-19T21:02Z",
    "lastModifiedDate" : "2018-10-18T16:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0792",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "v-webmail",
            "product" : {
              "product_data" : [ {
                "product_name" : "v-webmail",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.6.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.6.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18776",
          "name" : "18776",
          "refsource" : "SECUNIA",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/23260",
          "name" : "23260",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16706",
          "name" : "16706",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0639",
          "name" : "ADV-2006-0639",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24749",
          "name" : "vwebmail-preferencespersonal-xss(24749)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in preferences.personal.php in V-webmail 1.6.2 allows remote attackers to inject arbitrary web script or HTML via the newid parameter.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:v-webmail:v-webmail:1.6.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:v-webmail:v-webmail:1.6.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-19T21:02Z",
    "lastModifiedDate" : "2017-07-20T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0793",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "v-webmail",
            "product" : {
              "product_data" : [ {
                "product_name" : "v-webmail",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.6.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.6.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18776",
          "name" : "18776",
          "refsource" : "SECUNIA",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/23261",
          "name" : "23261",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16706",
          "name" : "16706",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0639",
          "name" : "ADV-2006-0639",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24753",
          "name" : "vwebmail-frameset-spoofing(24753)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "frameset.php in V-webmail 1.6.2 allows remote attackers to conduct phishing attacks by referencing arbitrary websites in the rframe parameter.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:v-webmail:v-webmail:1.6.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:v-webmail:v-webmail:1.6.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-19T21:02Z",
    "lastModifiedDate" : "2017-07-20T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0794",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "v-webmail",
            "product" : {
              "product_data" : [ {
                "product_name" : "v-webmail",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.6.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.6.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18776",
          "name" : "18776",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/23262",
          "name" : "23262",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0639",
          "name" : "ADV-2006-0639",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24754",
          "name" : "vwebmail-help-path-disclosure(24754)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "help.php in V-webmail 1.6.2 allows remote attackers to obtain the installation path via unspecified invalid parameters.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:v-webmail:v-webmail:1.6.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:v-webmail:v-webmail:1.6.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-19T21:02Z",
    "lastModifiedDate" : "2017-07-20T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0795",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "thomastsoi",
            "product" : {
              "product_data" : [ {
                "product_name" : "quirex",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.2",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-22"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://evuln.com/vulns/78/summary.html",
          "name" : "http://evuln.com/vulns/78/summary.html",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18926",
          "name" : "18926",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/426188/100/0/threaded",
          "name" : "20060226 [eVuln] Quirex Arbitrary File Disclosure Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16709",
          "name" : "16709",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0641",
          "name" : "ADV-2006-0641",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24672",
          "name" : "quirex-convert-information-disclosure(24672)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Absolute path traversal vulnerability in convert.cgi in Quirex 2.0.2 and earlier allows remote attackers to read arbitrary files, and possibly execute arbitrary code, via the (1) quiz_head, (2) quiz_foot, and (3) template variables."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:thomastsoi:quirex:2.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:thomastsoi:quirex:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "2.0.2"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-19T21:02Z",
    "lastModifiedDate" : "2018-10-18T16:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0796",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "clever_copy",
            "product" : {
              "product_data" : [ {
                "product_name" : "clever_copy",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18873",
          "name" : "18873",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/23235",
          "name" : "23235",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16681",
          "name" : "16681",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0616",
          "name" : "ADV-2006-0616",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24747",
          "name" : "clevercopy-subject-xss(24747)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in default.php in Clever Copy 3.0 allows remote attackers to inject arbitrary web script or HTML via the Subject field when sending private messages (privatemessages.php). NOTE: the provenance of this information is unknown; the details are obtained solely from third party information."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clever_copy:clever_copy:3.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-19T21:02Z",
    "lastModifiedDate" : "2017-07-20T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0797",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "nokia",
            "product" : {
              "product_data" : [ {
                "product_name" : "n70",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://archives.neohapsis.com/archives/fulldisclosure/2006-02/0316.html",
          "name" : "20060215 [ Secuobs - Advisory ] Another kind of DoS on Nokia cell phones",
          "refsource" : "FULLDISC",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18724",
          "name" : "18724",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/23061",
          "name" : "23061",
          "refsource" : "OSVDB",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.secuobs.com/news/15022006-nokia_n70.shtml#english",
          "name" : "http://www.secuobs.com/news/15022006-nokia_n70.shtml#english",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16666",
          "name" : "16666",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0538",
          "name" : "ADV-2006-0538",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24688",
          "name" : "nokia-bluetooth-l2cap-dos(24688)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Nokia N70 cell phone allows remote attackers to cause a denial of service (reboot or shutdown) through a wireless Bluetooth connection via a malformed Logical Link Control and Adaptation Protocol (L2CAP) packet whose length field is less than the actual length of the packet, possibly triggering a buffer overflow, as demonstrated using the Bluetooth Stack Smasher (BSS)."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:nokia:n70:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.8
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-19T21:02Z",
    "lastModifiedDate" : "2017-07-20T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0798",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "macallan",
            "product" : {
              "product_data" : [ {
                "product_name" : "mail_solution",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.8.03.025",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://macallan.club.fr/MMS/index.html",
          "name" : "http://macallan.club.fr/MMS/index.html",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18775",
          "name" : "18775",
          "refsource" : "SECUNIA",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/secunia_research/2006-4/advisory/",
          "name" : "http://secunia.com/secunia_research/2006-4/advisory/",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1015647",
          "name" : "1015647",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/23269",
          "name" : "23269",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16704",
          "name" : "16704",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0644",
          "name" : "ADV-2006-0644",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24761",
          "name" : "macallan-imap-directory-traversal(24761)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple directory traversal vulnerabilities in the IMAP service in Macallan Mail Solution before 4.8.05.004 allow remote authenticated users to read e-mails of other users or create, modify, or delete directories via a .. (dot dot) in the argument to the (1) CREATE, (2) SELECT, (3) DELETE, or (4) RENAME commands."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:macallan:mail_solution:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "4.8.03.025"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:P/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.5
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.0,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-19T21:02Z",
    "lastModifiedDate" : "2017-07-20T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0799",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "ie",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.0.2900",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.osvdb.org/23609",
          "name" : "23609",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/425298/100/0/threaded",
          "name" : "20060216 Internet Explorer Phishing mouseover issue",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/425386/100/0/threaded",
          "name" : "20060218 Re: Internet Explorer Phishing mouseover issue",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/425883/100/0/threaded",
          "name" : "20060223 Re: Internet Explorer Phishing mouseover issue",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/17938",
          "name" : "ie-ahref-status-spoofing(17938)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Microsoft Internet Explorer allows remote attackers to spoof a legitimate URL in the status bar and conduct a phishing attack via a web page with an anchor element with a legitimate \"href\" attribute, a form whose action points to a malicious URL, and an INPUT submit element that is modified to look like a legitimate URL.  NOTE: this issue is very similar to CVE-2004-1104, although the manipulations are slightly different."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:ie:6.0.2900:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:H/Au:N/C:P/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "HIGH",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 4.9,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2006-02-19T21:02Z",
    "lastModifiedDate" : "2018-10-18T16:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0800",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "postnuke_software_foundation",
            "product" : {
              "product_data" : [ {
                "product_name" : "postnuke",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.62",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.63",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.64",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.70",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.71",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.72",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.73",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.74",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.75",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.75_rc3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.76_rc4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.76_rc4a",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.76_rc4b",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.703",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.721",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.726.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.761",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.761a",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://archives.neohapsis.com/archives/fulldisclosure/2006-02/0469.html",
          "name" : "20060219 Multiple vulnerabilities in PostNuke <= 0.761",
          "refsource" : "FULLDISC",
          "tags" : [ ]
        }, {
          "url" : "http://news.postnuke.com/index.php?name=News&file=article&sid=2754",
          "name" : "http://news.postnuke.com/index.php?name=News&file=article&sid=2754",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://secunia.com/advisories/18937",
          "name" : "18937",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/454",
          "name" : "454",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16752",
          "name" : "16752",
          "refsource" : "BID",
          "tags" : [ "Exploit", "Patch" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0673",
          "name" : "ADV-2006-0673",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24823",
          "name" : "postnuke-user-nslanguages-xss(24823)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Interpretation conflict in PostNuke 0.761 and earlier allows remote attackers to conduct cross-site scripting (XSS) attacks via HTML tags with a trailing \"<\" character, which is interpreted as a \">\" character by some web browsers but bypasses the blacklist protection in (1) the pnVarCleanFromInput function in pnAPI.php, (2) the pnSecureInput function in pnAntiCracker.php, and (3) the htmltext parameter in an edituser operation to user.php."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postnuke_software_foundation:postnuke:0.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postnuke_software_foundation:postnuke:0.62:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postnuke_software_foundation:postnuke:0.63:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postnuke_software_foundation:postnuke:0.64:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postnuke_software_foundation:postnuke:0.70:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postnuke_software_foundation:postnuke:0.71:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postnuke_software_foundation:postnuke:0.72:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postnuke_software_foundation:postnuke:0.73:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postnuke_software_foundation:postnuke:0.74:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postnuke_software_foundation:postnuke:0.75:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postnuke_software_foundation:postnuke:0.75_rc3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postnuke_software_foundation:postnuke:0.76_rc4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postnuke_software_foundation:postnuke:0.76_rc4a:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postnuke_software_foundation:postnuke:0.76_rc4b:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postnuke_software_foundation:postnuke:0.703:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postnuke_software_foundation:postnuke:0.721:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postnuke_software_foundation:postnuke:0.726.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postnuke_software_foundation:postnuke:0.761:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postnuke_software_foundation:postnuke:0.761a:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:H/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "HIGH",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 2.6
        },
        "severity" : "LOW",
        "exploitabilityScore" : 4.9,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2006-02-20T22:02Z",
    "lastModifiedDate" : "2017-07-20T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0801",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "postnuke_software_foundation",
            "product" : {
              "product_data" : [ {
                "product_name" : "postnuke",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.761",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://archives.neohapsis.com/archives/fulldisclosure/2006-02/0469.html",
          "name" : "20060219 Multiple vulnerabilities in PostNuke <= 0.761",
          "refsource" : "FULLDISC",
          "tags" : [ ]
        }, {
          "url" : "http://news.postnuke.com/index.php?name=News&file=article&sid=2754",
          "name" : "http://news.postnuke.com/index.php?name=News&file=article&sid=2754",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18937",
          "name" : "18937",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/454",
          "name" : "454",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16752",
          "name" : "16752",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0673",
          "name" : "ADV-2006-0673",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24827",
          "name" : "postnuke-nslanguages-sql-injection(24827)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in the NS-Languages module for PostNuke 0.761 and earlier, when magic_quotes_gpc is off, allows remote attackers to execute arbitrary SQL commands via the language parameter to admin.php."
        }, {
          "lang" : "en",
          "value" : "Successful exploitation requires that the \"magic_quotes_gpc\" parameter is disabled."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postnuke_software_foundation:postnuke:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "0.761"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:H/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "HIGH",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.1
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 4.9,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-20T22:02Z",
    "lastModifiedDate" : "2017-07-20T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0802",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "postnuke_software_foundation",
            "product" : {
              "product_data" : [ {
                "product_name" : "postnuke",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.761",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://archives.neohapsis.com/archives/fulldisclosure/2006-02/0469.html",
          "name" : "20060219 Multiple vulnerabilities in PostNuke <= 0.761",
          "refsource" : "FULLDISC",
          "tags" : [ ]
        }, {
          "url" : "http://news.postnuke.com/index.php?name=News&file=article&sid=2754",
          "name" : "http://news.postnuke.com/index.php?name=News&file=article&sid=2754",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18937",
          "name" : "18937",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/454",
          "name" : "http://securityreason.com/securityalert/454",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16752",
          "name" : "16752",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0673",
          "name" : "ADV-2006-0673",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24823",
          "name" : "postnuke-user-nslanguages-xss(24823)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in the NS-Languages module for PostNuke 0.761 and earlier, when magic_quotes_gpc is enabled, allows remote attackers to inject arbitrary web script or HTML via the language parameter in a missing or translation operation."
        }, {
          "lang" : "en",
          "value" : "Successful exploitation requires that the \"magic_quotes_gpc\" parameter is disabled."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postnuke_software_foundation:postnuke:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "0.761"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:H/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "HIGH",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 2.6
        },
        "severity" : "LOW",
        "exploitabilityScore" : 4.9,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2006-02-20T22:02Z",
    "lastModifiedDate" : "2017-07-20T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0803",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "novell",
            "product" : {
              "product_data" : [ {
                "product_name" : "suse_linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "suse",
            "product" : {
              "product_data" : [ {
                "product_name" : "suse_linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9.3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.novell.com/linux/security/advisories/2006_09_gpg.html",
          "name" : "SUSE-SA:2006:009",
          "refsource" : "SUSE",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.novell.com/linux/security/advisories/2006_13_gpg.html",
          "name" : "SUSE-SA:2006:013",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16889",
          "name" : "16889",
          "refsource" : "BID",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The signature verification functionality in the YaST Online Update (YOU) script handling relies on a gpg feature that is not intended for signature verification, which prevents YOU from detecting malicious scripts or code that do not pass the signature check when gpg 1.4.x is being used."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:novell:suse_linux:10.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:suse:suse_linux:9.3:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-23T20:02Z",
    "lastModifiedDate" : "2018-10-30T16:25Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0804",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "tin",
            "product" : {
              "product_data" : [ {
                "product_name" : "tin",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0_pl0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0_pl1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0_pl2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0_pl3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0_pl4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0_pl5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1_pl0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1_pl1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1_pl2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1_pl3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1_pl4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1_pl5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1_pl6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1_pl7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1_pl8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1_pl9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2_pl0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2_pl1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2_pl2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.6.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.6.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.8.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/19130",
          "name" : "19130",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://security.gentoo.org/glsa/glsa-200611-18.xml",
          "name" : "GLSA-200611-18",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://www.novell.com/linux/security/advisories/2006_05_sr.html",
          "name" : "SUSE-SR:2006:005",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://www.openpkg.org/security/OpenPKG-SA-2006.005-tin.html",
          "name" : "OpenPKG-SA-2006.005",
          "refsource" : "OPENPKG",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16728",
          "name" : "16728",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0702",
          "name" : "ADV-2006-0702",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24841",
          "name" : "tin-offbyone-bo(24841)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Off-by-one error in TIN 1.8.0 and earlier might allow attackers to execute arbitrary code via unknown vectors that trigger a buffer overflow."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tin:tin:1.0_pl0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tin:tin:1.0_pl1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tin:tin:1.0_pl2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tin:tin:1.0_pl3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tin:tin:1.0_pl4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tin:tin:1.0_pl5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tin:tin:1.1_pl0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tin:tin:1.1_pl1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tin:tin:1.1_pl2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tin:tin:1.1_pl3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tin:tin:1.1_pl4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tin:tin:1.1_pl5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tin:tin:1.1_pl6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tin:tin:1.1_pl7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tin:tin:1.1_pl8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tin:tin:1.1_pl9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tin:tin:1.2_pl0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tin:tin:1.2_pl1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tin:tin:1.2_pl2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tin:tin:1.4.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tin:tin:1.4.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tin:tin:1.4.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tin:tin:1.4.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tin:tin:1.4.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tin:tin:1.4.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tin:tin:1.4.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tin:tin:1.4.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tin:tin:1.6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tin:tin:1.6.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tin:tin:1.6.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tin:tin:1.8.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-21T01:02Z",
    "lastModifiedDate" : "2017-07-20T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0805",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "francisco_burzi",
            "product" : {
              "product_data" : [ {
                "product_name" : "php-nuke",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.5_beta1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.5_final",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.5_rc1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.5_rc2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.5_rc3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0_final",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.9",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18936",
          "name" : "18936",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/455",
          "name" : "455",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/425394/100/0/threaded",
          "name" : "20060218 [waraxe-2006-SA#045] - Bypassing CAPTCHA in phpNuke 6.x-7.9",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16722",
          "name" : "16722",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.waraxe.us/advisory-45.html",
          "name" : "http://www.waraxe.us/advisory-45.html",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The CAPTCHA functionality in php-Nuke 6.0 through 7.9 uses fixed challenge/response pairs that only vary once per day based on the User Agent (HTTP_USER_AGENT), which allows remote attackers to bypass CAPTCHA controls by fixing the User Agent, performing a valid challenge/response, then replaying that pair in the random_num and gfx_check parameters."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:francisco_burzi:php-nuke:6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:francisco_burzi:php-nuke:6.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:francisco_burzi:php-nuke:6.5_beta1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:francisco_burzi:php-nuke:6.5_final:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:francisco_burzi:php-nuke:6.5_rc1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:francisco_burzi:php-nuke:6.5_rc2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:francisco_burzi:php-nuke:6.5_rc3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:francisco_burzi:php-nuke:6.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:francisco_burzi:php-nuke:6.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:francisco_burzi:php-nuke:6.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:francisco_burzi:php-nuke:7.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:francisco_burzi:php-nuke:7.0_final:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:francisco_burzi:php-nuke:7.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:francisco_burzi:php-nuke:7.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:francisco_burzi:php-nuke:7.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:francisco_burzi:php-nuke:7.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:francisco_burzi:php-nuke:7.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:francisco_burzi:php-nuke:7.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:francisco_burzi:php-nuke:7.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:francisco_burzi:php-nuke:7.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:francisco_burzi:php-nuke:7.9:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-21T02:02Z",
    "lastModifiedDate" : "2018-10-18T16:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0806",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "john_lim",
            "product" : {
              "product_data" : [ {
                "product_name" : "adodb",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.66",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.68",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.70",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.71",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://phpesp.cvs.sourceforge.net/phpesp/phpESP/admin/include/lib/adodb/adodb-pager.inc.php?r1=1.1&r2=1.2",
          "name" : "http://phpesp.cvs.sourceforge.net/phpesp/phpESP/admin/include/lib/adodb/adodb-pager.inc.php?r1=1.1&r2=1.2",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18928",
          "name" : "18928",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/19555",
          "name" : "19555",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/19590",
          "name" : "19590",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/19591",
          "name" : "19591",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/19691",
          "name" : "19691",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/452",
          "name" : "452",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://sourceforge.net/project/shownotes.php?release_id=419843&group_id=8956",
          "name" : "http://sourceforge.net/project/shownotes.php?release_id=419843&group_id=8956",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2006/dsa-1029",
          "name" : "DSA-1029",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2006/dsa-1030",
          "name" : "DSA-1030",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2006/dsa-1031",
          "name" : "DSA-1031",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.gentoo.org/security/en/glsa/glsa-200604-07.xml",
          "name" : "GLSA-200604-07",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://www.gulftech.org/?node=research&article_id=00101-02182006",
          "name" : "http://www.gulftech.org/?node=research&article_id=00101-02182006",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/23362",
          "name" : "23362",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/425393/100/0/threaded",
          "name" : "20060218 ADOdb Library Cross Site Scripting",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16720",
          "name" : "16720",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0664",
          "name" : "ADV-2006-0664",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/2021",
          "name" : "ADV-2006-2021",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple cross-site scripting (XSS) vulnerabilities in ADOdb 4.71, as used in multiple packages such as phpESP, allow remote attackers to inject arbitrary web script or HTML via (1) the next_page parameter in adodb-pager.inc.php and (2) other unspecified vectors related to PHP_SELF."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:john_lim:adodb:4.66:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:john_lim:adodb:4.68:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:john_lim:adodb:4.70:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:john_lim:adodb:4.71:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-21T02:02Z",
    "lastModifiedDate" : "2018-10-18T16:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0807",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "njstar",
            "product" : {
              "product_data" : [ {
                "product_name" : "chinese_word_processor",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.01.41108",
                    "version_affected" : "<="
                  } ]
                }
              }, {
                "product_name" : "japanese_word_processor",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.01.41108",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18702",
          "name" : "18702",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/secunia_research/2006-5/advisory/",
          "name" : "http://secunia.com/secunia_research/2006-5/advisory/",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/461",
          "name" : "461",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1015649",
          "name" : "1015649",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.njstar.com/njstar/chinese/",
          "name" : "http://www.njstar.com/njstar/chinese/",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.njstar.com/njstar/japanese/",
          "name" : "http://www.njstar.com/njstar/japanese/",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/23354",
          "name" : "23354",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/425498/100/0/threaded",
          "name" : "20060220 Secunia Research: NJStar Word Processor Font Name Buffer Overflow",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16737",
          "name" : "16737",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0670",
          "name" : "ADV-2006-0670",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24773",
          "name" : "njstar-font-name-bo(24773)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Stack-based buffer overflow in NJStar Chinese and Japanese Word Processor 4.x and 5.x before 5.10 allows user-assisted attackers to execute arbitrary code via font names in NJStar (.njx) documents."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:njstar:chinese_word_processor:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "5.01.41108"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:njstar:japanese_word_processor:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "5.01.41108"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:H/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "HIGH",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.1
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 4.9,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2006-02-21T02:02Z",
    "lastModifiedDate" : "2018-10-18T16:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0808",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "mute",
            "product" : {
              "product_data" : [ {
                "product_name" : "mute",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.4",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://cvs.sourceforge.net/viewcvs.py/mute-net/MUTE/doc/notes/notes.txt?view=markup",
          "name" : "http://cvs.sourceforge.net/viewcvs.py/mute-net/MUTE/doc/notes/notes.txt?view=markup",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18980",
          "name" : "18980",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/23336",
          "name" : "23336",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24931",
          "name" : "mute-mwebcache-security-bypass(24931)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "MUTE 0.4 allows remote attackers to cause a denial of service (messages not forwarded) and obtain sensitive information about a target by filling a client's mWebCache cache with malicious \"zombie\" nodes."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mute:mute:0.4:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.4
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-21T02:02Z",
    "lastModifiedDate" : "2017-07-20T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0809",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "skate_board",
            "product" : {
              "product_data" : [ {
                "product_name" : "skate_board",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.9",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://evuln.com/vulns/84/summary.html",
          "name" : "http://evuln.com/vulns/84/summary.html",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18978",
          "name" : "18978",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/540",
          "name" : "540",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/23301",
          "name" : "23301",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/23302",
          "name" : "23302",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/23303",
          "name" : "23303",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/426658/30/0/threaded",
          "name" : "20060303 [eVuln] Skate Board Multimple Vulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16936",
          "name" : "16936",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24778",
          "name" : "skateboard-sendpass-sql-injection(24778)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24779",
          "name" : "skateboard-authentication-bypass(24779)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple SQL injection vulnerabilities in Skate Board 0.9 allow remote attackers to execute arbitrary SQL commands via the (1) usern parameter in (a) sendpass.php, and the (2) usern and (3) passwd parameters and (4) sf_cookie cookie in (b) login.php and (c) logged.php."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:skate_board:skate_board:0.9:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-21T02:02Z",
    "lastModifiedDate" : "2017-07-20T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0810",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "skate_board",
            "product" : {
              "product_data" : [ {
                "product_name" : "skate_board",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.9",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://evuln.com/vulns/84/summary.html",
          "name" : "http://evuln.com/vulns/84/summary.html",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18978",
          "name" : "18978",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/540",
          "name" : "540",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/23304",
          "name" : "23304",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/426658/30/0/threaded",
          "name" : "20060303 [eVuln] Skate Board Multimple Vulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16936",
          "name" : "16936",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24780",
          "name" : "skateboard-config-file-include(24780)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in config.php in Skate Board 0.9 allows remote authenticated administrators to execute arbitrary PHP code by causing certain variables in config.php to be modified, possibly due to XSS or direct static code injection."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:skate_board:skate_board:0.9:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:S/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 3.5
        },
        "severity" : "LOW",
        "exploitabilityScore" : 6.8,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-21T02:02Z",
    "lastModifiedDate" : "2017-07-20T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0811",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "skate_board",
            "product" : {
              "product_data" : [ {
                "product_name" : "skate_board",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.9",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://evuln.com/vulns/84/summary.html",
          "name" : "http://evuln.com/vulns/84/summary.html",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18978",
          "name" : "18978",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/540",
          "name" : "540",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/23305",
          "name" : "23305",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/426658/30/0/threaded",
          "name" : "20060303 [eVuln] Skate Board Multimple Vulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16936",
          "name" : "16936",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24781",
          "name" : "skateboard-registration-xss(24781)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in reguser.php in Skate Board 0.9 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters involved with the registration form."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:skate_board:skate_board:0.9:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-21T02:02Z",
    "lastModifiedDate" : "2017-07-20T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0812",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "visnetic",
            "product" : {
              "product_data" : [ {
                "product_name" : "visnetic_antivirus_plug-in_for_mail_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.6.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.6.1.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/16583",
          "name" : "16583",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/secunia_research/2005-65/advisory/",
          "name" : "http://secunia.com/secunia_research/2005-65/advisory/",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1015670",
          "name" : "1015670",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/425890/100/0/threaded",
          "name" : "20060223 Secunia Research: Visnetic AntiVirus Plug-in for MailServerPrivilege Escalation",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16788",
          "name" : "16788",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0701",
          "name" : "ADV-2006-0701",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24928",
          "name" : "visnetic-av-plugin-privilege-elevation(24928)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The VisNetic AntiVirus Plug-in (DKAVUpSch.exe) for Mail Server 4.6.0.4, 4.6.1.1, and possibly other versions before 4.6.1.2, does not drop privileges before executing other programs, which allows local users to gain privileges."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:visnetic:visnetic_antivirus_plug-in_for_mail_server:4.6.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:visnetic:visnetic_antivirus_plug-in_for_mail_server:4.6.1.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.2
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 3.9,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-23T20:02Z",
    "lastModifiedDate" : "2018-10-18T16:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0813",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "winace",
            "product" : {
              "product_data" : [ {
                "product_name" : "winace",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.60",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/17251",
          "name" : "17251",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/secunia_research/2005-67/advisory/",
          "name" : "http://secunia.com/secunia_research/2005-67/advisory/",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/479",
          "name" : "479",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1015672",
          "name" : "1015672",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/23383",
          "name" : "23383",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/425894/100/0/threaded",
          "name" : "20060223 Secunia Research: WinACE ARJ Archive Handling Buffer Overflow",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16786",
          "name" : "16786",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0709",
          "name" : "ADV-2006-0709",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24872",
          "name" : "winace-arj-header-bo(24872)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Heap-based buffer overflow in WinACE 2.60 allows user-assisted attackers to execute arbitrary code via a large header block in an ARJ archive."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:winace:winace:2.60:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:H/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "HIGH",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.1
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 4.9,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2006-02-24T11:02Z",
    "lastModifiedDate" : "2018-10-18T16:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0814",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "lighttpd",
            "product" : {
              "product_data" : [ {
                "product_name" : "lighttpd",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.16",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.10",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18886",
          "name" : "18886",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/secunia_research/2006-9/advisory/",
          "name" : "http://secunia.com/secunia_research/2006-9/advisory/",
          "refsource" : "MISC",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/523",
          "name" : "523",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1015703",
          "name" : "1015703",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://trac.lighttpd.net/trac/changeset/1005",
          "name" : "http://trac.lighttpd.net/trac/changeset/1005",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/23542",
          "name" : "23542",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/426446/100/0/threaded",
          "name" : "20060301 Secunia Research: Lighttpd Script Source Disclosure Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16893",
          "name" : "16893",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0782",
          "name" : "ADV-2006-0782",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24976",
          "name" : "lighttpd-source-code-disclosure(24976)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "response.c in Lighttpd 1.4.10 and possibly previous versions, when run on Windows, allows remote attackers to read arbitrary source code via requests that contain trailing (1) \".\" (dot) and (2) space characters, which are ignored by Windows, as demonstrated by PHP files."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:lighttpd:lighttpd:1.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:lighttpd:lighttpd:1.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:lighttpd:lighttpd:1.1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:lighttpd:lighttpd:1.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:lighttpd:lighttpd:1.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:lighttpd:lighttpd:1.1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:lighttpd:lighttpd:1.1.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:lighttpd:lighttpd:1.1.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:lighttpd:lighttpd:1.1.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:lighttpd:lighttpd:1.1.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:lighttpd:lighttpd:1.1.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:lighttpd:lighttpd:1.1.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:lighttpd:lighttpd:1.2.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:lighttpd:lighttpd:1.2.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:lighttpd:lighttpd:1.2.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:lighttpd:lighttpd:1.2.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:lighttpd:lighttpd:1.2.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:lighttpd:lighttpd:1.2.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:lighttpd:lighttpd:1.2.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:lighttpd:lighttpd:1.2.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:lighttpd:lighttpd:1.2.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:lighttpd:lighttpd:1.3.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:lighttpd:lighttpd:1.3.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:lighttpd:lighttpd:1.3.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:lighttpd:lighttpd:1.3.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:lighttpd:lighttpd:1.3.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:lighttpd:lighttpd:1.3.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:lighttpd:lighttpd:1.3.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:lighttpd:lighttpd:1.3.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:lighttpd:lighttpd:1.3.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:lighttpd:lighttpd:1.3.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:lighttpd:lighttpd:1.3.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:lighttpd:lighttpd:1.3.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:lighttpd:lighttpd:1.3.12:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:lighttpd:lighttpd:1.3.13:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:lighttpd:lighttpd:1.3.14:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:lighttpd:lighttpd:1.3.15:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:lighttpd:lighttpd:1.3.16:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:lighttpd:lighttpd:1.4.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:lighttpd:lighttpd:1.4.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:lighttpd:lighttpd:1.4.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:lighttpd:lighttpd:1.4.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:lighttpd:lighttpd:1.4.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:lighttpd:lighttpd:1.4.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:lighttpd:lighttpd:1.4.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:lighttpd:lighttpd:1.4.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:lighttpd:lighttpd:1.4.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:lighttpd:lighttpd:1.4.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:lighttpd:lighttpd:1.4.10:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-03-06T21:02Z",
    "lastModifiedDate" : "2018-10-18T16:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0815",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "networkactiv",
            "product" : {
              "product_data" : [ {
                "product_name" : "networkactiv_web_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.5.15",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18947",
          "name" : "18947",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/secunia_research/2006-10/advisory",
          "name" : "http://secunia.com/secunia_research/2006-10/advisory",
          "refsource" : "MISC",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.networkactiv.com/WebServer.html",
          "name" : "http://www.networkactiv.com/WebServer.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/426461/100/0/threaded",
          "name" : "20060301 Secunia Research: NetworkActiv Web Server Script Source DisclosureVulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16895",
          "name" : "16895",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0783",
          "name" : "ADV-2006-0783",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24979",
          "name" : "networkactiv-script-source-disclosure(24979)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "NetworkActiv Web Server 3.5.15 allows remote attackers to read script source code via a crafted URL with a \"/\" (forward slash) after the file extension."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:networkactiv:networkactiv_web_server:3.5.15:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-03-06T23:02Z",
    "lastModifiedDate" : "2018-10-18T16:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0816",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "orionserver",
            "product" : {
              "product_data" : [ {
                "product_name" : "orion_application_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0.6",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://archives.neohapsis.com/archives/fulldisclosure/2006-03/1455.html",
          "name" : "20060323 Secunia Research: Orion Application Server JSP Source Disclosure Vulnerability",
          "refsource" : "FULLDISC",
          "tags" : [ "Broken Link", "Third Party Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18950",
          "name" : "18950",
          "refsource" : "SECUNIA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://secunia.com/secunia_research/2006-11/advisory/",
          "name" : "http://secunia.com/secunia_research/2006-11/advisory/",
          "refsource" : "MISC",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1015823",
          "name" : "1015823",
          "refsource" : "SECTRACK",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.osvdb.org/24053",
          "name" : "24053",
          "refsource" : "OSVDB",
          "tags" : [ "Broken Link" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/428601/100/0/threaded",
          "name" : "20060323 Secunia Research: Orion Application Server JSP Source DisclosureVulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/17204",
          "name" : "17204",
          "refsource" : "BID",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/1055",
          "name" : "ADV-2006-1055",
          "refsource" : "VUPEN",
          "tags" : [ "Broken Link", "Third Party Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/25405",
          "name" : "orion-jsp-source-disclosure(25405)",
          "refsource" : "XF",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Orion Application Server before 2.0.7, when running on Windows, allows remote attackers to obtain the source code of JSP files via (1) . (dot) and (2) space characters in the extension of a URL."
        }, {
          "lang" : "en",
          "value" : "Update to version 2.0.7 or contact the vendor for a patch."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:orionserver:orion_application_server:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "2.0.6"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-03-24T11:02Z",
    "lastModifiedDate" : "2018-10-18T16:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0817",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "deerfield",
            "product" : {
              "product_data" : [ {
                "product_name" : "visnetic_mail_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.3.5",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "icewarp",
            "product" : {
              "product_data" : [ {
                "product_name" : "web_mail",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.6.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "merak",
            "product" : {
              "product_data" : [ {
                "product_name" : "mail_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.3.8r",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18953",
          "name" : "18953",
          "refsource" : "SECUNIA",
          "tags" : [ "Exploit", "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18966",
          "name" : "18966",
          "refsource" : "SECUNIA",
          "tags" : [ "Exploit", "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/secunia_research/2006-12/advisory/",
          "name" : "http://secunia.com/secunia_research/2006-12/advisory/",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/secunia_research/2006-14/advisory/",
          "name" : "http://secunia.com/secunia_research/2006-14/advisory/",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1016513",
          "name" : "1016513",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1016514",
          "name" : "1016514",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/27328",
          "name" : "27328",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/440297/100/0/threaded",
          "name" : "20060717 Secunia Research: IceWarp Web Mail Two File InclusionVulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/440302/100/0/threaded",
          "name" : "20060717 Secunia Research: VisNetic Mail Server Two File InclusionVulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/19002",
          "name" : "19002",
          "refsource" : "BID",
          "tags" : [ "Exploit", "Patch" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/19007",
          "name" : "19007",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/2825",
          "name" : "ADV-2006-2825",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/2826",
          "name" : "ADV-2006-2826",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/27773",
          "name" : "visnetic-include-file-include(27773)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Absolute path directory traversal vulnerability in (a) MERAK Mail Server for Windows 8.3.8r with before IceWarp Web Mail 5.6.1 and (b) VisNetic MailServer before 8.5.0.5 allows remote attackers to include arbitrary files via a full Windows path and drive letter in the (1) language parameter in accounts/inc/include.php and (2) lang_settings parameter in admin/inc/include.php, which is not properly sanitized by the securepath function, a related issue to CVE-2005-4556."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:deerfield:visnetic_mail_server:8.3.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:icewarp:web_mail:5.6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:merak:mail_server:8.3.8r:*:windows:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-07-21T14:03Z",
    "lastModifiedDate" : "2018-10-18T16:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0818",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "deerfield",
            "product" : {
              "product_data" : [ {
                "product_name" : "visnetic_mail_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.3.5",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "icewarp",
            "product" : {
              "product_data" : [ {
                "product_name" : "web_mail",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.6.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "merak",
            "product" : {
              "product_data" : [ {
                "product_name" : "mail_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.3.8r",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18953",
          "name" : "18953",
          "refsource" : "SECUNIA",
          "tags" : [ "Exploit", "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18966",
          "name" : "18966",
          "refsource" : "SECUNIA",
          "tags" : [ "Exploit", "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/secunia_research/2006-12/advisory/",
          "name" : "http://secunia.com/secunia_research/2006-12/advisory/",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/secunia_research/2006-14/advisory/",
          "name" : "http://secunia.com/secunia_research/2006-14/advisory/",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1016513",
          "name" : "1016513",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1016514",
          "name" : "1016514",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/440297/100/0/threaded",
          "name" : "20060717 Secunia Research: IceWarp Web Mail Two File InclusionVulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/440302/100/0/threaded",
          "name" : "20060717 Secunia Research: VisNetic Mail Server Two File InclusionVulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/19002",
          "name" : "19002",
          "refsource" : "BID",
          "tags" : [ "Exploit", "Patch" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/19007",
          "name" : "19007",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/2825",
          "name" : "ADV-2006-2825",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/27780",
          "name" : "visnetic-language-file-include(27780)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Absolute path directory traversal vulnerability in (1) MERAK Mail Server for Windows 8.3.8r with before IceWarp Web Mail 5.6.1 and (2) VisNetic MailServer before 8.5.0.5 allows remote authenticated users to include arbitrary files via a modified language parameter and a full Windows or UNC pathname in the lang_settings parameter to mail/index.html, which is not properly sanitized by the validatefolder PHP function, possibly due to an incomplete fix for CVE-2005-4558."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:deerfield:visnetic_mail_server:8.3.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:icewarp:web_mail:5.6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:merak:mail_server:8.3.8r:*:windows:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-07-21T14:03Z",
    "lastModifiedDate" : "2018-10-18T16:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0819",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "gnome",
            "product" : {
              "product_data" : [ {
                "product_name" : "dwarf_http_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.3.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18962",
          "name" : "18962",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/secunia_research/2006-13/advisory",
          "name" : "http://secunia.com/secunia_research/2006-13/advisory",
          "refsource" : "MISC",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/576",
          "name" : "576",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1015779",
          "name" : "1015779",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/23836",
          "name" : "23836",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/427478/100/0/threaded",
          "name" : "20060313 Secunia Research: Dwarf HTTP Server Source Disclosure andCross-Site Scripting",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/17123",
          "name" : "17123",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0937",
          "name" : "ADV-2006-0937",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/25178",
          "name" : "dwarfhttp-extension-information-disclosure(25178)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Dwarf HTTP Server 1.3.2 allows remote attackers to obtain the source code of JSP files via (1) dot, (2) space, (3) slash, or (4) NULL characters in the filename extension of an HTTP request."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:gnome:dwarf_http_server:1.3.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 7.8
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-03-13T19:34Z",
    "lastModifiedDate" : "2018-10-18T16:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0820",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "gnome",
            "product" : {
              "product_data" : [ {
                "product_name" : "dwarf_http_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.3.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18962",
          "name" : "18962",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/secunia_research/2006-13/advisory",
          "name" : "http://secunia.com/secunia_research/2006-13/advisory",
          "refsource" : "MISC",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1015779",
          "name" : "1015779",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/23837",
          "name" : "23837",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/427478/100/0/threaded",
          "name" : "20060313 Secunia Research: Dwarf HTTP Server Source Disclosure andCross-Site Scripting",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/17123",
          "name" : "17123",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0937",
          "name" : "ADV-2006-0937",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/25179",
          "name" : "dwarfhttp-url-xss(25179)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in Dwarf HTTP Server 1.3.2 allows remote attackers to inject arbitrary web script or HTML via unspecified error messages."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:gnome:dwarf_http_server:1.3.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-03-13T19:34Z",
    "lastModifiedDate" : "2018-10-18T16:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0821",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "bxcp",
            "product" : {
              "product_data" : [ {
                "product_name" : "bxcp",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.299",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18929",
          "name" : "18929",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0660",
          "name" : "ADV-2006-0660",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24783",
          "name" : "bxcp-tid-sql-injection(24783)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/1513",
          "name" : "1513",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in index.php in BXCP 0.299 allows remote attackers to execute arbitrary SQL commands via the tid parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:bxcp:bxcp:0.299:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-21T23:02Z",
    "lastModifiedDate" : "2017-10-19T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0822",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "emulinker_kaillera_server",
            "product" : {
              "product_data" : [ {
                "product_name" : "emulinker_kaillera_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.97.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.98.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.98.5",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18938",
          "name" : "18938",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://sourceforge.net/project/shownotes.php?release_id=394690&group_id=127754",
          "name" : "http://sourceforge.net/project/shownotes.php?release_id=394690&group_id=127754",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16733",
          "name" : "16733",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0665",
          "name" : "ADV-2006-0665",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24784",
          "name" : "emulinker-packet-handling-dos(24784)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in EmuLinker Kaillera Server before 0.99.17 allows remote attackers to cause a denial of service (probably resource consumption) via a crafted packet that causes a \"ghost game\" to be left on the server."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:emulinker_kaillera_server:emulinker_kaillera_server:0.97.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:emulinker_kaillera_server:emulinker_kaillera_server:0.98.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:emulinker_kaillera_server:emulinker_kaillera_server:0.98.5:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-21T23:02Z",
    "lastModifiedDate" : "2017-07-20T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0823",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "geeklog",
            "product" : {
              "product_data" : [ {
                "product_name" : "geeklog",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.3.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.11_sr1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.11_sr2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.11_sr3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18920",
          "name" : "18920",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.geeklog.net/article.php/geeklog-1.4.0sr1",
          "name" : "http://www.geeklog.net/article.php/geeklog-1.4.0sr1",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.gulftech.org/?node=research&article_id=00102-02192006",
          "name" : "http://www.gulftech.org/?node=research&article_id=00102-02192006",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/23348",
          "name" : "23348",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/425506/100/0/threaded",
          "name" : "20060219 Geeklog Remote Code Execution",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16755",
          "name" : "16755",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0661",
          "name" : "ADV-2006-0661",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24775",
          "name" : "geeklog-users-sessions-sql-injection(24775)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple SQL injection vulnerabilities in Geeklog 1.4.0 before 1.4.0sr1 and 1.3.11 before 1.3.11sr4 allow remote attackers to inject arbitrary SQL commands via the (1) userid variable to users.php or (2) sessid variable to lib-sessions.php."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:geeklog:geeklog:1.3.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:geeklog:geeklog:1.3.11_sr1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:geeklog:geeklog:1.3.11_sr2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:geeklog:geeklog:1.3.11_sr3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:geeklog:geeklog:1.4.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-21T23:02Z",
    "lastModifiedDate" : "2018-10-18T16:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0824",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "geeklog",
            "product" : {
              "product_data" : [ {
                "product_name" : "geeklog",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.3.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.11_sr1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.11_sr2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.11_sr3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18920",
          "name" : "18920",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.geeklog.net/article.php/geeklog-1.4.0sr1",
          "name" : "http://www.geeklog.net/article.php/geeklog-1.4.0sr1",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.gulftech.org/?node=research&article_id=00102-02192006",
          "name" : "http://www.gulftech.org/?node=research&article_id=00102-02192006",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/23349",
          "name" : "23349",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/425506/100/0/threaded",
          "name" : "20060219 Geeklog Remote Code Execution",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16755",
          "name" : "16755",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0661",
          "name" : "ADV-2006-0661",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple unspecified vulnerabilities in lib-common.php in Geeklog 1.4.0 before 1.4.0sr1 and 1.3.11 before 1.3.11sr4 allow remote attackers to include arbitrary local files and execute arbitrary code via (1) absolute paths in unspecified parameters and (2) the language cookie, as demonstrated for code execution using error.log."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:geeklog:geeklog:1.3.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:geeklog:geeklog:1.3.11_sr1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:geeklog:geeklog:1.3.11_sr2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:geeklog:geeklog:1.3.11_sr3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:geeklog:geeklog:1.4.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-21T23:02Z",
    "lastModifiedDate" : "2018-10-18T16:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0825",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "xerox",
            "product" : {
              "product_data" : [ {
                "product_name" : "workcentre_232",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "workcentre_238",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "workcentre_245",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "workcentre_255",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "workcentre_265",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "workcentre_275",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18952",
          "name" : "18952",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1015648",
          "name" : "1015648",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/23359",
          "name" : "23359",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16726",
          "name" : "16726",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0668",
          "name" : "ADV-2006-0668",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.xerox.com/downloads/usa/en/c/cert_XRX06_001.pdf",
          "name" : "http://www.xerox.com/downloads/usa/en/c/cert_XRX06_001.pdf",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24804",
          "name" : "xerox-workcentre-auth-bypass(24804)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple unspecified vulnerabilities in ESS/ Network Controller and MicroServer Web Server in Xerox WorkCentre Pro and Xerox WorkCentre running software 13.027.24.015 and 14.027.24.015 allow remote attackers to bypass authentication or gain \"unauthorized network access\" via unknown attack vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:xerox:workcentre_232:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:xerox:workcentre_232:*:*:pro:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:xerox:workcentre_238:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:xerox:workcentre_238:*:*:pro:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:xerox:workcentre_245:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:xerox:workcentre_245:*:*:pro:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:xerox:workcentre_255:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:xerox:workcentre_255:*:*:pro:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:xerox:workcentre_265:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:xerox:workcentre_265:*:*:pro:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:xerox:workcentre_275:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:xerox:workcentre_275:*:*:pro:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-21T23:02Z",
    "lastModifiedDate" : "2017-07-20T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0826",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "xerox",
            "product" : {
              "product_data" : [ {
                "product_name" : "workcentre_232",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "workcentre_238",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "workcentre_245",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "workcentre_255",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "workcentre_265",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "workcentre_275",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18952",
          "name" : "18952",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1015648",
          "name" : "1015648",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16723",
          "name" : "16723",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0668",
          "name" : "ADV-2006-0668",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.xerox.com/downloads/usa/en/c/cert_XRX06_001.pdf",
          "name" : "http://www.xerox.com/downloads/usa/en/c/cert_XRX06_001.pdf",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24805",
          "name" : "xerox-workcentre-postscript-dos(24805)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in ESS/ Network Controller and MicroServer Web Server in Xerox WorkCentre Pro and Xerox WorkCentre running software 13.027.24.015 and 14.027.24.015 allows remote attackers to cause a denial of service via a crafted Postscript request."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:xerox:workcentre_232:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:xerox:workcentre_232:*:*:pro:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:xerox:workcentre_238:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:xerox:workcentre_238:*:*:pro:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:xerox:workcentre_245:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:xerox:workcentre_245:*:*:pro:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:xerox:workcentre_255:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:xerox:workcentre_255:*:*:pro:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:xerox:workcentre_265:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:xerox:workcentre_265:*:*:pro:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:xerox:workcentre_275:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:xerox:workcentre_275:*:*:pro:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-21T23:02Z",
    "lastModifiedDate" : "2017-07-20T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0827",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "xerox",
            "product" : {
              "product_data" : [ {
                "product_name" : "workcentre_232",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "workcentre_238",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "workcentre_245",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "workcentre_255",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "workcentre_265",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "workcentre_275",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18952",
          "name" : "18952",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16727",
          "name" : "16727",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0668",
          "name" : "ADV-2006-0668",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.xerox.com/downloads/usa/en/c/cert_XRX06_001.pdf",
          "name" : "http://www.xerox.com/downloads/usa/en/c/cert_XRX06_001.pdf",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24806",
          "name" : "xerox-workcentre-xss(24806)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting vulnerability in ESS/ Network Controller and MicroServer Web Server in Xerox WorkCentre Pro and Xerox WorkCentre running software 13.027.24.015 and 14.027.24.015 allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:xerox:workcentre_232:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:xerox:workcentre_232:*:*:pro:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:xerox:workcentre_238:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:xerox:workcentre_238:*:*:pro:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:xerox:workcentre_245:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:xerox:workcentre_245:*:*:pro:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:xerox:workcentre_255:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:xerox:workcentre_255:*:*:pro:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:xerox:workcentre_265:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:xerox:workcentre_265:*:*:pro:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:xerox:workcentre_275:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:xerox:workcentre_275:*:*:pro:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-21T23:02Z",
    "lastModifiedDate" : "2017-07-20T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0828",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "xerox",
            "product" : {
              "product_data" : [ {
                "product_name" : "workcentre_232",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "workcentre_238",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "workcentre_245",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "workcentre_255",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "workcentre_265",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "workcentre_275",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18952",
          "name" : "18952",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1015648",
          "name" : "1015648",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0668",
          "name" : "ADV-2006-0668",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.xerox.com/downloads/usa/en/c/cert_XRX06_001.pdf",
          "name" : "http://www.xerox.com/downloads/usa/en/c/cert_XRX06_001.pdf",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in ESS/ Network Controller and MicroServer Web Server in Xerox WorkCentre Pro and Xerox WorkCentre running software 13.027.24.015 and 14.027.24.015 allows remote attackers to \"reduce effectiveness of security features\" via unknown attack vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:xerox:workcentre_232:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:xerox:workcentre_232:*:*:pro:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:xerox:workcentre_238:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:xerox:workcentre_238:*:*:pro:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:xerox:workcentre_245:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:xerox:workcentre_245:*:*:pro:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:xerox:workcentre_255:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:xerox:workcentre_255:*:*:pro:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:xerox:workcentre_265:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:xerox:workcentre_265:*:*:pro:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:xerox:workcentre_275:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:xerox:workcentre_275:*:*:pro:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-21T23:02Z",
    "lastModifiedDate" : "2011-03-08T02:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0829",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "e-blah",
            "product" : {
              "product_data" : [ {
                "product_name" : "platinum",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9.7",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://evuln.com/vulns/83/summary.html",
          "name" : "http://evuln.com/vulns/83/summary.html",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18992",
          "name" : "18992",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/528",
          "name" : "528",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.eblah.com/forum/m-1140116897/",
          "name" : "http://www.eblah.com/forum/m-1140116897/",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.osvdb.org/23299",
          "name" : "23299",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/426582/100/0/threaded",
          "name" : "20060302 [eVuln] E-Blah Platinum 'Referer' XSS Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16713",
          "name" : "16713",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0638",
          "name" : "ADV-2006-0638",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24777",
          "name" : "eblah-httpreferer-xss(24777)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting vulnerability in E-Blah Platinum 9.7 allows remote attackers to inject arbitrary web script or HTML via the referer (HTTP_REFERER), which is not sanitized when the log file is viewed by the administrator using \"Click Log\"."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:e-blah:platinum:9.7:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-21T23:02Z",
    "lastModifiedDate" : "2018-10-18T16:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0830",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "ie",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.0.2900",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/archive/1/425283/100/0/threaded",
          "name" : "20060216 Stack overflow vulnerability in Internet Explorer exploitable trough VBScript and JScript scripting engines.",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/425378/100/0/threaded",
          "name" : "20060218 Re: Stack overflow vulnerability in Internet Explorer exploitable trough VBScript and JScript scripting engines.",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16687",
          "name" : "16687",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24788",
          "name" : "ie-script-engine-stack-dos(24788)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The scripting engine in Internet Explorer allows remote attackers to cause a denial of service (resource consumption) and possibly execute arbitrary code via a web page that contains a recurrent call to an infinite loop in Javascript or VBscript, which consumes the stack, as demonstrated by resetting the \"location\" variable within the loop."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:ie:6.0.2900:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-21T23:02Z",
    "lastModifiedDate" : "2018-10-18T16:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0831",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "tasarim_rehberi",
            "product" : {
              "product_data" : [ {
                "product_name" : "tasarim_rehberi",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/archive/1/425389/100/0/threaded",
          "name" : "20060218 Tasarim Rehberi Index.PHP Remote Command Exucetion",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "PHP remote file include vulnerability in index.php in Tasarim Rehberi allows remote attackers to execute arbitrary PHP code via a URL in the (1) sayfaadi or (2) sayfa parameter.  NOTE: this might be a site-specific issue.  If so, it should not be included in CVE."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tasarim_rehberi:tasarim_rehberi:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-21T23:02Z",
    "lastModifiedDate" : "2018-10-18T16:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0832",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "wpc.easy",
            "product" : {
              "product_data" : [ {
                "product_name" : "wpc.easy",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18945",
          "name" : "18945",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/456",
          "name" : "456",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/425395/100/0/threaded",
          "name" : "20060218 SLQ Injection vulnerability in WPCeasy",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16721",
          "name" : "16721",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0662",
          "name" : "ADV-2006-0662",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple SQL injection vulnerabilities in admin.asp in WPC.easy allow remote attackers to execute arbitrary SQL commands via the (1) uid and (2) pwd parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:wpc.easy:wpc.easy:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-22T00:02Z",
    "lastModifiedDate" : "2018-10-18T16:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0833",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "boonex",
            "product" : {
              "product_data" : [ {
                "product_name" : "barracuda_directory",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18965",
          "name" : "18965",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/23372",
          "name" : "23372",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16746",
          "name" : "16746",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0674",
          "name" : "ADV-2006-0674",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24807",
          "name" : "barracuda-multiple-xss(24807)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple cross-site scripting (XSS) vulnerabilities in Barracuda Directory 1.1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors to the (1) Add URL and (2) Suggest Category module.  NOTE: the provenance of this information is unknown; portions of the details are obtained from third party information."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:boonex:barracuda_directory:1.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-22T00:02Z",
    "lastModifiedDate" : "2017-07-20T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0834",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "uniden",
            "product" : {
              "product_data" : [ {
                "product_name" : "uip1868p",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/archive/1/425362/100/0/threaded",
          "name" : "20060216 Uniden UIP1868P (VoIP phone/gateway) default easy-to-guess password vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24786",
          "name" : "uniden-uip1868p-default-account(24786)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Uniden UIP1868P VoIP Telephone and Router has a default password of admin for the web-based configuration utility, which allows remote attackers to obtain sensitive information on the device such as telephone numbers called, and possibly connect to other hosts.  NOTE: it is possible that this password was configured by a reseller, not the original vendor; if so, then this is not a vulnerability in the product."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:uniden:uip1868p:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-22T02:02Z",
    "lastModifiedDate" : "2018-10-18T16:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0835",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "mitridat",
            "product" : {
              "product_data" : [ {
                "product_name" : "web_calendar_pro",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://archives.neohapsis.com/archives/fulldisclosure/2006-02/0340.html",
          "name" : "20060215 Web Calendar Pro - Denial of Service SQL Injection Vulnerability",
          "refsource" : "FULLDISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://secunia.com/advisories/18902",
          "name" : "18902",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16789",
          "name" : "16789",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0700",
          "name" : "ADV-2006-0700",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://www.xorcrew.net/xpa/XPA-WebCalendarPro.txt",
          "name" : "http://www.xorcrew.net/xpa/XPA-WebCalendarPro.txt",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24729",
          "name" : "webcalendarpro-dropbase-sql-injection(24729)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in dropbase.php in MitriDAT Web Calendar Pro allows remote attackers to modify internal SQL queries and cause a denial of service (inaccessible database) via the tabls parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mitridat:web_calendar_pro:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-22T02:02Z",
    "lastModifiedDate" : "2017-07-20T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0836",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "mozilla",
            "product" : {
              "product_data" : [ {
                "product_name" : "thunderbird",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.5",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://archives.neohapsis.com/archives/fulldisclosure/2006-02/0399.html",
          "name" : "20060217 Mozila Thunderbird 1.5 Address Book DoS",
          "refsource" : "FULLDISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://securityreason.com/securityalert/469",
          "name" : "469",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/425602/100/0/threaded",
          "name" : "20060221 Mozila Thunderbird 1.5 Address Book DoS",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16716",
          "name" : "16716",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24810",
          "name" : "thunderbird-address-book-dos(24810)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Mozilla Thunderbird 1.5 allows user-assisted attackers to cause an unspecified denial of service by tricking the user into importing an LDIF file with a long field into the address book, as demonstrated by a long homePhone field."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:thunderbird:1.5:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:H/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "HIGH",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 2.6
        },
        "severity" : "LOW",
        "exploitabilityScore" : 4.9,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2006-02-22T02:02Z",
    "lastModifiedDate" : "2018-10-18T16:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0837",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "micromuse",
            "product" : {
              "product_data" : [ {
                "product_name" : "netcool_neusecure",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.0.236",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://archives.neohapsis.com/archives/fulldisclosure/2006-02/0364.html",
          "name" : "20060216 Password disclosure and remote access in Netcool/NeuSecure Security information management platform",
          "refsource" : "FULLDISC",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18922",
          "name" : "18922",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1015642",
          "name" : "1015642",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/23270",
          "name" : "23270",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/23271",
          "name" : "23271",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/23914",
          "name" : "23914",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/425304/100/0/threaded",
          "name" : "20060216 Password disclosure and remote access in Netcool/NeuSecure Security information management platform",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16693",
          "name" : "16693",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16700",
          "name" : "16700",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24785",
          "name" : "netcool-neosecure-config-weak-permission(24785)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "IBM Tivoli Micromuse Netcool/NeuSecure 3.0.236 has world-readable permissions for (1) /etc/neusecure.conf, (2) /opt/NeuSecure/etc/cms-3.0.236.buildconf, and (3) /opt/NeuSecure/bin/ns_archiver.log, which allows local users to read sensitive information such as passwords.  NOTE: IBM has privately confirmed to CVE that a fix is available for these issues."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:micromuse:netcool_neusecure:3.0.236:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 2.1
        },
        "severity" : "LOW",
        "exploitabilityScore" : 3.9,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-22T02:02Z",
    "lastModifiedDate" : "2018-10-18T16:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0838",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "micromuse",
            "product" : {
              "product_data" : [ {
                "product_name" : "netcool_neusecure",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.0.236",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://archives.neohapsis.com/archives/fulldisclosure/2006-02/0364.html",
          "name" : "20060216 Password disclosure and remote access in Netcool/NeuSecure Security information management platform",
          "refsource" : "FULLDISC",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18922",
          "name" : "18922",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1015642",
          "name" : "1015642",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/23270",
          "name" : "23270",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/23271",
          "name" : "23271",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/425304/100/0/threaded",
          "name" : "20060216 Password disclosure and remote access in Netcool/NeuSecure Security information management platform",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16693",
          "name" : "16693",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16698",
          "name" : "16698",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24785",
          "name" : "netcool-neosecure-config-weak-permission(24785)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24787",
          "name" : "netcool-neosecure-plaintext-password(24787)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "IBM Tivoli Micromuse Netcool/NeuSecure 3.0.236 stores cleartext passwords in the (1) CMS_DBPASS, (2) CMSM_DBPASS, and (3) RPT_DBPASS fields in /etc/neusecure.conf, and in (4) /opt/NeuSecure/bin/ns_archiver.log, which allows local users to gain privileges.  NOTE: IBM has privately confirmed to CVE that a fix is available for these issues."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:micromuse:netcool_neusecure:3.0.236:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 2.1
        },
        "severity" : "LOW",
        "exploitabilityScore" : 3.9,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-22T02:02Z",
    "lastModifiedDate" : "2018-10-18T16:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0839",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "sourcefire",
            "product" : {
              "product_data" : [ {
                "product_name" : "snort",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.4.3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18959",
          "name" : "18959",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/425290/100/0/threaded",
          "name" : "20060217 SNORT Incorrect fragmented packet reassembly",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16705",
          "name" : "16705",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24811",
          "name" : "snort-frag3-detection-bypass(24811)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The frag3 preprocessor in Sourcefire Snort 2.4.3 does not properly reassemble certain fragmented packets with IP options, which allows remote attackers to evade detection of certain attacks, possibly related to IP option lengths."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sourcefire:snort:2.4.3:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-22T02:02Z",
    "lastModifiedDate" : "2018-10-18T16:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0840",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "mantis",
            "product" : {
              "product_data" : [ {
                "product_name" : "mantis",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.9.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.9.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.10.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.10.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.10.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.11.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.11.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.12.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.13.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.13.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.14.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.14.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.14.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.14.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.14.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.14.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.14.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.14.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.14.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.15.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.15.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.15.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.16",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.16.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.17",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.17.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.17.4a",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.18",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.18.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.18.0_rc1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.18.0a1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.18.0a2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.18.0a3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.18.0a4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.18.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.18.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.18.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.18a1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.19.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.19.0_rc1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.19.0a",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.19.0a1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.19.0a2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.19.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.19.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.19.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.19.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.0_rc1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.0_rc2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.0_rc3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.0_rc4",
                    "version_affected" : "<="
                  }, {
                    "version_value" : "1.0.0a1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.0a2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.0a3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://morph3us.org/advisories/20060214-mantis-100rc4.txt",
          "name" : "http://morph3us.org/advisories/20060214-mantis-100rc4.txt",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://sourceforge.net/project/showfiles.php?group_id=14963&package_id=12175&release_id=386059",
          "name" : "http://sourceforge.net/project/showfiles.php?group_id=14963&package_id=12175&release_id=386059",
          "refsource" : "MISC",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://sourceforge.net/project/shownotes.php?release_id=386059&group_id=14963",
          "name" : "http://sourceforge.net/project/shownotes.php?release_id=386059&group_id=14963",
          "refsource" : "MISC",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/425046/100/0/threaded",
          "name" : "20060215 [BuHa-Security] Multiple Vulnerabilities in Mantis 1.00rc4",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16657",
          "name" : "16657",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24726",
          "name" : "mantis-manageuserpagesql-injection(24726)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "manage_user_page.php in Mantis 1.00rc4 and earlier does not properly handle a sort parameter containing a ' (quote) character, which allows remote attackers to trigger a SQL error that may be repeatedly reported to a user who makes subsequent web accesses with the MANTIS_MANAGE_COOKIE cookie.  NOTE: this issue might be the same as vector 2 in CVE-2005-4519."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.9.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.9.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.10.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.10.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.10.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.11.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.11.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.12:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.12.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.13:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.13.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.13.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.14:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.14.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.14.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.14.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.14.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.14.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.14.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.14.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.14.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.14.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.15:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.15.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.15.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.15.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.16:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.16.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.17:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.17.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.17.4a:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.18:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.18.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.18.0_rc1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.18.0a1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.18.0a2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.18.0a3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.18.0a4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.18.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.18.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.18.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.18a1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.19.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.19.0_rc1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.19.0a:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.19.0a1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.19.0a2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.19.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.19.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.19.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.19.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:1.0.0_rc1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:1.0.0_rc2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:1.0.0_rc3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.0.0_rc4"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:1.0.0a1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:1.0.0a2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:1.0.0a3:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-22T02:02Z",
    "lastModifiedDate" : "2018-10-18T16:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0841",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "mantis",
            "product" : {
              "product_data" : [ {
                "product_name" : "mantis",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.9.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.9.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.10.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.10.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.10.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.11.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.11.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.12.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.13.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.13.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.14.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.14.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.14.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.14.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.14.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.14.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.14.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.14.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.14.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.15.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.15.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.15.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.16",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.16.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.17",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.17.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.17.4a",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.18",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.18.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.18.0_rc1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.18.0a1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.18.0a2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.18.0a3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.18.0a4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.18.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.18.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.18.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.18a1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.19.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.19.0_rc1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.19.0a",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.19.0a1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.19.0a2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.19.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.19.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.19.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.19.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.0_rc1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.0_rc2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.0_rc3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.0_rc4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.0a1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.0a2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.0a3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://morph3us.org/advisories/20060214-mantis-100rc4.txt",
          "name" : "http://morph3us.org/advisories/20060214-mantis-100rc4.txt",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/21400",
          "name" : "21400",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://sourceforge.net/project/showfiles.php?group_id=14963&package_id=12175&release_id=386059",
          "name" : "http://sourceforge.net/project/showfiles.php?group_id=14963&package_id=12175&release_id=386059",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://sourceforge.net/project/shownotes.php?release_id=386059&group_id=14963",
          "name" : "http://sourceforge.net/project/shownotes.php?release_id=386059&group_id=14963",
          "refsource" : "MISC",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.debian.org/security/2006/dsa-1133",
          "name" : "DSA-1133",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/22487",
          "name" : "22487",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/23248",
          "name" : "23248",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/425046/100/0/threaded",
          "name" : "20060215 [BuHa-Security] Multiple Vulnerabilities in Mantis 1.00rc4",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16657",
          "name" : "16657",
          "refsource" : "BID",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple cross-site scripting (XSS) vulnerabilities in Mantis 1.00rc4 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) hide_status, (2) handler_id, (3) user_monitor, (4) reporter_id, (5) view_type, (6) show_severity, (7) show_category, (8) show_status, (9) show_resolution, (10) show_build, (11) show_profile, (12) show_priority, (13) highlight_changed, (14) relationship_type, and (15) relationship_bug parameters in (a) view_all_set.php; the (16) sort parameter in (b) manage_user_page.php; the (17) view_type parameter in (c) view_filters_page.php; and the (18) title parameter in (d) proj_doc_delete.php.  NOTE: item 17 might be subsumed by CVE-2005-4522."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.9.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.9.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.10.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.10.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.10.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.11.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.11.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.12:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.12.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.13:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.13.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.13.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.14:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.14.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.14.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.14.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.14.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.14.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.14.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.14.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.14.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.14.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.15:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.15.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.15.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.15.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.16:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.16.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.17:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.17.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.17.4a:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.18:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.18.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.18.0_rc1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.18.0a1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.18.0a2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.18.0a3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.18.0a4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.18.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.18.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.18.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.18a1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.19.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.19.0_rc1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.19.0a:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.19.0a1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.19.0a2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.19.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.19.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.19.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:0.19.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:1.0.0_rc1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:1.0.0_rc2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:1.0.0_rc3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:1.0.0_rc4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:1.0.0a1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:1.0.0a2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mantis:mantis:1.0.0a3:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-22T02:02Z",
    "lastModifiedDate" : "2018-10-18T16:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0842",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "calacode",
            "product" : {
              "product_data" : [ {
                "product_name" : "atmail_webmail_system",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18874",
          "name" : "18874",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/23236",
          "name" : "23236",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16683",
          "name" : "16683",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0617",
          "name" : "ADV-2006-0617",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24742",
          "name" : "@mail-html-image-xss(24742)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in Calacode @Mail 4.3 allows remote attackers to inject arbitrary web script or HTML via a modified javascript: string in the SRC attribute of an IMG element in an e-mail message, as demonstrated by \"java&#09;script:.\"  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information."
        }, {
          "lang" : "en",
          "value" : "Successful exploitation of this issue requires a victim user has @Mail configured to display images in email messages."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:calacode:atmail_webmail_system:4.3:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2006-02-22T02:02Z",
    "lastModifiedDate" : "2017-07-20T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0843",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "leif_m._wright",
            "product" : {
              "product_data" : [ {
                "product_name" : "web_blog",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.5",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18923",
          "name" : "18923",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/522",
          "name" : "522",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.evuln.com/vulns/82/summary.html",
          "name" : "http://www.evuln.com/vulns/82/summary.html",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16712",
          "name" : "16712",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24752",
          "name" : "webblog-txt-obtain-information(24752)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Leif M. Wright's Blog 3.5 stores the config file and other txt files under the web root with insufficient access control, which allows remote attackers to read the administrator's password."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:leif_m._wright:web_blog:3.5:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-22T02:02Z",
    "lastModifiedDate" : "2017-07-20T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0844",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "leif_m._wright",
            "product" : {
              "product_data" : [ {
                "product_name" : "web_blog",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.5",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18923",
          "name" : "18923",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/522",
          "name" : "522",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.evuln.com/vulns/82/summary.html",
          "name" : "http://www.evuln.com/vulns/82/summary.html",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16714",
          "name" : "16714",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24755",
          "name" : "webblog-cookie-auth-bypass(24755)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Leif M. Wright's Blog 3.5 does not make a password comparison when authenticating an administrator via a cookie, which allows remote attackers to bypass login authentication, probably by setting the blogAdmin cookie."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:leif_m._wright:web_blog:3.5:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-22T02:02Z",
    "lastModifiedDate" : "2017-07-20T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0845",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "leif_m._wright",
            "product" : {
              "product_data" : [ {
                "product_name" : "web_blog",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.5",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18923",
          "name" : "18923",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/522",
          "name" : "522",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.evuln.com/vulns/82/summary.html",
          "name" : "http://www.evuln.com/vulns/82/summary.html",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24757",
          "name" : "webblog-sendmail-command-execution(24757)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Leif M. Wright's Blog 3.5 allows remote authenticated users with administrative privileges to execute arbitrary programs, including shell commands, by configuring the sendmail path to a malicious pathname."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:leif_m._wright:web_blog:3.5:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.5
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-22T02:02Z",
    "lastModifiedDate" : "2017-07-20T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0846",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "leif_m._wright",
            "product" : {
              "product_data" : [ {
                "product_name" : "web_blog",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.5",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18923",
          "name" : "18923",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/522",
          "name" : "522",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.evuln.com/vulns/82/summary.html",
          "name" : "http://www.evuln.com/vulns/82/summary.html",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16715",
          "name" : "16715",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24758",
          "name" : "webblog-headers-xss(24758)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple cross-site scripting (XSS) vulnerabilities in Leif M. Wright's Blog 3.5 allow remote attackers to inject arbitrary web script or HTML via the (1) Referer and (2) User-Agent HTTP headers, which are stored in a log file and not sanitized when the administrator views the \"Log\" page, possibly using the ViewCommentsLog function."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:leif_m._wright:web_blog:3.5:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-22T02:02Z",
    "lastModifiedDate" : "2017-07-20T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0847",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "cherrypy",
            "product" : {
              "product_data" : [ {
                "product_name" : "cherrypy",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8_beta",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.9_beta",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.9_gamma",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.9_rc1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.10_beta",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.10_rc1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.0a1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.1.0_beta",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.1.0_rc1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.1.0_rc2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://groups.google.com/group/cherrypy-announce/browse_thread/thread/92b2972f774fe6df/2f63afc9433dc306#2f63afc9433dc306",
          "name" : "http://groups.google.com/group/cherrypy-announce/browse_thread/thread/92b2972f774fe6df/2f63afc9433dc306#2f63afc9433dc306",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://secunia.com/advisories/18944",
          "name" : "18944",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/20344",
          "name" : "20344",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://sourceforge.net/project/shownotes.php?release_id=384316&group_id=56099",
          "name" : "http://sourceforge.net/project/shownotes.php?release_id=384316&group_id=56099",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.cherrypy.org/",
          "name" : "http://www.cherrypy.org/",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.gentoo.org/security/en/glsa/glsa-200605-16.xml",
          "name" : "GLSA-200605-16",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16760",
          "name" : "16760",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0677",
          "name" : "ADV-2006-0677",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24809",
          "name" : "cherrypy-staticfilter-directory-traversal(24809)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Directory traversal vulnerability in the staticfilter component in CherryPy before 2.1.1 allows remote attackers to read arbitrary files via \"..\" sequences in unspecified vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cherrypy:cherrypy:0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cherrypy:cherrypy:0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cherrypy:cherrypy:0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cherrypy:cherrypy:0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cherrypy:cherrypy:0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cherrypy:cherrypy:0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cherrypy:cherrypy:0.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cherrypy:cherrypy:0.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cherrypy:cherrypy:0.8_beta:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cherrypy:cherrypy:0.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cherrypy:cherrypy:0.9_beta:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cherrypy:cherrypy:0.9_gamma:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cherrypy:cherrypy:0.9_rc1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cherrypy:cherrypy:0.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cherrypy:cherrypy:0.10_beta:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cherrypy:cherrypy:0.10_rc1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cherrypy:cherrypy:2.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cherrypy:cherrypy:2.0.0a1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cherrypy:cherrypy:2.1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cherrypy:cherrypy:2.1.0_beta:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cherrypy:cherrypy:2.1.0_rc1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cherrypy:cherrypy:2.1.0_rc2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-22T02:02Z",
    "lastModifiedDate" : "2017-07-20T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0848",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apple",
            "product" : {
              "product_data" : [ {
                "product_name" : "mac_os_x",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.4.5",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "mac_os_x_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.4.5",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-16"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://docs.info.apple.com/article.html?artnum=303382",
          "name" : "http://docs.info.apple.com/article.html?artnum=303382",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18963",
          "name" : "18963",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1015652",
          "name" : "1015652",
          "refsource" : "SECTRACK",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.frsirt.com/exploits/20060222.safari_safefiles_exec.pm.php",
          "name" : "http://www.frsirt.com/exploits/20060222.safari_safefiles_exec.pm.php",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://www.heise.de/english/newsticker/news/69862",
          "name" : "http://www.heise.de/english/newsticker/news/69862",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.kb.cert.org/vuls/id/999708",
          "name" : "VU#999708",
          "refsource" : "CERT-VN",
          "tags" : [ "Third Party Advisory", "US Government Resource" ]
        }, {
          "url" : "http://www.mathematik.uni-ulm.de/numerik/staff/lehn/macosx.html",
          "name" : "http://www.mathematik.uni-ulm.de/numerik/staff/lehn/macosx.html",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/23510",
          "name" : "23510",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16736",
          "name" : "16736",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA06-053A.html",
          "name" : "TA06-053A",
          "refsource" : "CERT",
          "tags" : [ "Third Party Advisory", "US Government Resource" ]
        }, {
          "url" : "http://www.us-cert.gov/cas/techalerts/TA06-062A.html",
          "name" : "TA06-062A",
          "refsource" : "CERT",
          "tags" : [ "US Government Resource" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0671",
          "name" : "ADV-2006-0671",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24808",
          "name" : "macosx-zip-command-execution(24808)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The \"Open 'safe' files after downloading\" option in Safari on Apple Mac OS X allows remote user-assisted attackers to execute arbitrary commands by tricking a user into downloading a __MACOSX folder that contains metadata (resource fork) that invokes the Terminal, which automatically interprets the script using bash, as demonstrated using a ZIP file that contains a script with a safe file extension."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:10.4.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x_server:10.4.5:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:H/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "HIGH",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.1
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 4.9,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2006-02-22T23:02Z",
    "lastModifiedDate" : "2017-07-20T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0850",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ilch.de",
            "product" : {
              "product_data" : [ {
                "product_name" : "ilchclan",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.4",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18951",
          "name" : "18951",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.ilch.de/news-134.html",
          "name" : "http://www.ilch.de/news-134.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/23370",
          "name" : "23370",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0676",
          "name" : "ADV-2006-0676",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24830",
          "name" : "ilchclan-login-sql-injection(24830)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in include/includes/user/login.php in ilchClan before 1.05g allows remote attackers to execute arbitrary SQL commands via the login_name parameter.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ilch.de:ilchclan:0.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ilch.de:ilchclan:1.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ilch.de:ilchclan:1.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ilch.de:ilchclan:1.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ilch.de:ilchclan:1.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ilch.de:ilchclan:1.0.4:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-23T02:06Z",
    "lastModifiedDate" : "2017-07-20T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0851",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ilch.de",
            "product" : {
              "product_data" : [ {
                "product_name" : "ilchclan",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.4",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18951",
          "name" : "18951",
          "refsource" : "SECUNIA",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/23369",
          "name" : "23369",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16735",
          "name" : "16735",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0672",
          "name" : "ADV-2006-0672",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24829",
          "name" : "ilchclan-index-sql-injection(24829)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/1516",
          "name" : "1516",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in the forum module of ilchClan 1.05g and earlier allows remote attackers to execute arbitrary SQL commands via the pid parameter, when creating a newpost."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ilch.de:ilchclan:0.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ilch.de:ilchclan:1.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ilch.de:ilchclan:1.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ilch.de:ilchclan:1.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ilch.de:ilchclan:1.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ilch.de:ilchclan:1.0.4:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-23T02:06Z",
    "lastModifiedDate" : "2017-10-19T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0852",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "devscripts",
            "product" : {
              "product_data" : [ {
                "product_name" : "admbook",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.2.2",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18930",
          "name" : "18930",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16753",
          "name" : "16753",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0663",
          "name" : "ADV-2006-0663",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24771",
          "name" : "admbook-index-command-execution(24771)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/1512",
          "name" : "1512",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Direct static code injection vulnerability in write.php in Admbook 1.2.2 and earlier allows remote attackers to execute arbitrary PHP code via the X-Forwarded-For HTTP header field, which is inserted into content-data.php."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:devscripts:admbook:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.2.2"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-23T02:06Z",
    "lastModifiedDate" : "2017-10-19T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0853",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "truenorth_software",
            "product" : {
              "product_data" : [ {
                "product_name" : "ia_emailserver",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "corporate_5.3.4",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18986",
          "name" : "18986",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1015664",
          "name" : "1015664",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/23377",
          "name" : "23377",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/425586/100/0/threaded",
          "name" : "20060220 [AJECT] TrueNorth IA eMailserver 5.3.4 buffer overflow vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16744",
          "name" : "16744",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0686",
          "name" : "ADV-2006-0686",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24812",
          "name" : "ia-emailserver-imap-bo(24812)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Buffer overflow in the IMAP service of TrueNorth Internet Anywhere (IA) eMailserver 5.3.4 allows remote authenticated users to cause a denial of service (crash) and possibly execute arbitrary code via a long SEARCH argument."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:truenorth_software:ia_emailserver:corporate_5.3.4:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.5
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-23T02:06Z",
    "lastModifiedDate" : "2018-10-18T16:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0854",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "intensive_point",
            "product" : {
              "product_data" : [ {
                "product_name" : "iuser_ecommerce",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-94"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://archives.neohapsis.com/archives/fulldisclosure/2006-02/0339.html",
          "name" : "20060215 iUser Ecommerce - Remote Command Execution Vulnerability",
          "refsource" : "FULLDISC",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18903",
          "name" : "18903",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/23429",
          "name" : "23429",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16787",
          "name" : "16787",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0699",
          "name" : "ADV-2006-0699",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.xorcrew.net/xpa/XPA-iUser.txt",
          "name" : "http://www.xorcrew.net/xpa/XPA-iUser.txt",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24724",
          "name" : "iuser-ecommerce-file-include(24724)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "PHP remote file inclusion vulnerability in common.php in Intensive Point iUser Ecommerce allows remote attackers to include arbitrary files via a URL in the include_path variable, which is not initialized before being used."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:intensive_point:iuser_ecommerce:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-23T02:06Z",
    "lastModifiedDate" : "2017-07-20T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0855",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "rahul_dhesi",
            "product" : {
              "product_data" : [ {
                "product_name" : "zoo",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.10",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://archives.neohapsis.com/archives/bugtraq/2006-04/0061.html",
          "name" : "20060403 Barracuda ZOO archiver security bug leads to remote compromise",
          "refsource" : "BUGTRAQ",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/19002",
          "name" : "19002",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/19130",
          "name" : "19130",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/19148",
          "name" : "19148",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/19166",
          "name" : "19166",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/19408",
          "name" : "19408",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/19514",
          "name" : "19514",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/546",
          "name" : "546",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1015668",
          "name" : "1015668",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1015866",
          "name" : "1015866",
          "refsource" : "SECTRACK",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.debian.org/security/2006/dsa-991",
          "name" : "DSA-991",
          "refsource" : "DEBIAN",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.gentoo.org/security/en/glsa/glsa-200603-05.xml",
          "name" : "GLSA-200603-05",
          "refsource" : "GENTOO",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.guay-leroux.com/projects/barracuda-advisory-ZOO.txt",
          "name" : "http://www.guay-leroux.com/projects/barracuda-advisory-ZOO.txt",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://www.guay-leroux.com/projects/zoo-advisory.txt",
          "name" : "http://www.guay-leroux.com/projects/zoo-advisory.txt",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://www.novell.com/linux/security/advisories/2006_05_sr.html",
          "name" : "SUSE-SR:2006:005",
          "refsource" : "SUSE",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.novell.com/linux/security/advisories/2006_06_sr.html",
          "name" : "SUSE-SR:2006:006",
          "refsource" : "SUSE",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/425887/100/0/threaded",
          "name" : "20060223 zoo contains exploitable buffer overflows",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16790",
          "name" : "16790",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0705",
          "name" : "ADV-2006-0705",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/1220",
          "name" : "ADV-2006-1220",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24904",
          "name" : "zoo-misc-bo(24904)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Stack-based buffer overflow in the fullpath function in misc.c for zoo 2.10 and earlier, as used in products such as Barracuda Spam Firewall, allows user-assisted attackers to execute arbitrary code via a crafted ZOO file that causes the combine function to return a longer string than expected."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rahul_dhesi:zoo:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "2.10"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:H/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "HIGH",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.1
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 4.9,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2006-02-23T21:02Z",
    "lastModifiedDate" : "2018-10-18T16:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0856",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "scriptme",
            "product" : {
              "product_data" : [ {
                "product_name" : "sme_gb_host",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.21",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18823",
          "name" : "18823",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.evuln.com/vulns/66/summary.html",
          "name" : "http://www.evuln.com/vulns/66/summary.html",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/425317/100/0/threaded",
          "name" : "20060216 [eVuln] SmE GB Host Authentication Bypass Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16609",
          "name" : "16609",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0543",
          "name" : "ADV-2006-0543",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24544",
          "name" : "smegbhost-login-sql-injection(24544)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in login.php in Scriptme SmE GB Host 1.21 allows remote attackers to execute arbitrary SQL commands and bypass authentication via the Username parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:scriptme:sme_gb_host:1.21:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-23T23:02Z",
    "lastModifiedDate" : "2018-10-18T16:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0857",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "e107",
            "product" : {
              "product_data" : [ {
                "product_name" : "chatbox_plugin",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "e107",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.7.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/archive/1/425388/100/0/threaded",
          "name" : "20060218 e107 CMS 0.7.2 Chatbox plugin XSS vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16719",
          "name" : "16719",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24815",
          "name" : "e107-chatbox-xss(24815)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in Chatbox Plugin 1.0 in e107 0.7.2 allows remote attackers to inject arbitrary HTML or web script via a Chatbox, as demonstrated using a SCRIPT element."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:e107:chatbox_plugin:1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:e107:e107:0.7.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-23T23:02Z",
    "lastModifiedDate" : "2018-10-18T16:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0858",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "starforce",
            "product" : {
              "product_data" : [ {
                "product_name" : "safe_n_sec_personal_+_anti-spyware",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secdev.zoller.lu/research/safnsec.htm",
          "name" : "http://secdev.zoller.lu/research/safnsec.htm",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/425504/100/0/threaded",
          "name" : "20060219 [TZO-062006] Safe'nVulnerable",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16762",
          "name" : "16762",
          "refsource" : "BID",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unquoted Windows search path vulnerability in (1) snsmcon.exe, (2) the autostartup mechanism, and (3) an unspecified installation component in StarForce Safe'n'Sec Personal + Anti-Spyware 2.0 and earlier, and possibly other StarForce Safe'n'Sec products, might allow local users to gain privileges via a malicious \"program\" file in the C: folder."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:starforce:safe_n_sec_personal_\\+_anti-spyware:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "2.0"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.2
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 3.9,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-23T23:02Z",
    "lastModifiedDate" : "2018-10-18T16:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0859",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "michael_salzer",
            "product" : {
              "product_data" : [ {
                "product_name" : "guestbox",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.6",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-264"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18946",
          "name" : "18946",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/23374",
          "name" : "23374",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/425495/100/0/threaded",
          "name" : "20060220 Guestbox XSS/an admin bypass",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/426663/100/0/threaded",
          "name" : "20060302 Re: Guestbox XSS/an admin bypass",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0675",
          "name" : "ADV-2006-0675",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24797",
          "name" : "guestbox-admin-access(24797)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Michael Salzer Guestbox 0.6, and other versions before 0.8, allows remote attackers to post an admin comment to a guestbook entry via a certain modified form, possibly related to the nummer parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:michael_salzer:guestbox:0.6:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-23T23:02Z",
    "lastModifiedDate" : "2018-10-18T16:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0860",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "michael_salzer",
            "product" : {
              "product_data" : [ {
                "product_name" : "guestbox",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.6",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18946",
          "name" : "18946",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/23375",
          "name" : "23375",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/425495/100/0/threaded",
          "name" : "20060220 Guestbox XSS/an admin bypass",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/426663/100/0/threaded",
          "name" : "20060302 Re: Guestbox XSS/an admin bypass",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16751",
          "name" : "16751",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0675",
          "name" : "ADV-2006-0675",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24798",
          "name" : "guestbox-gbshow-xss(24798)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple cross-site scripting (XSS) vulnerabilities in Michael Salzer Guestbox 0.6, and other versions before 0.8, allow remote attackers to inject arbitrary web script or HTML via (1) HTML tags that follow a \"http://\" string, which bypasses a regular expression check, and (2) other unspecified attack vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:michael_salzer:guestbox:0.6:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-23T23:02Z",
    "lastModifiedDate" : "2018-10-18T16:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0861",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "michael_salzer",
            "product" : {
              "product_data" : [ {
                "product_name" : "guestbox",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.6",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-200"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18946",
          "name" : "18946",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/460",
          "name" : "460",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/23376",
          "name" : "23376",
          "refsource" : "OSVDB",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/425495/100/0/threaded",
          "name" : "20060220 Guestbox XSS/an admin bypass",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/426663/100/0/threaded",
          "name" : "20060302 Re: Guestbox XSS/an admin bypass",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0675",
          "name" : "ADV-2006-0675",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24799",
          "name" : "guestbox-gblog-obtain-information(24799)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Michael Salzer Guestbox 0.6, and other versions before 0.8, allows remote attackers to obtain the source IP addresses of guestbook entries via a direct request to /gb/gblog."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:michael_salzer:guestbox:0.6:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-23T23:02Z",
    "lastModifiedDate" : "2018-10-19T17:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0862",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "infovista",
            "product" : {
              "product_data" : [ {
                "product_name" : "portalse",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0_build_20087",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18994",
          "name" : "18994",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1015669",
          "name" : "1015669",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.irmplc.com/advisory017.htm",
          "name" : "http://www.irmplc.com/advisory017.htm",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/425779/100/0/threaded",
          "name" : "20060222 IRM 017: Multiple Vulnerabilities in Infovista Portal SE",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16776",
          "name" : "16776",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0695",
          "name" : "ADV-2006-0695",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24893",
          "name" : "vistaportal-parameter-directory-traversal(24893)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in InfoVista PortalSE 2.0 Build 20087 on Solaris 8 without the IV00038969 hotfix allows remote attackers to read arbitrary files via a crafted URL."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:infovista:portalse:2.0_build_20087:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-23T23:02Z",
    "lastModifiedDate" : "2018-10-18T16:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0863",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "infovista",
            "product" : {
              "product_data" : [ {
                "product_name" : "portalse",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0_build_20087",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18994",
          "name" : "18994",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/473",
          "name" : "473",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1015669",
          "name" : "1015669",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.irmplc.com/advisory017.htm",
          "name" : "http://www.irmplc.com/advisory017.htm",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/425779/100/0/threaded",
          "name" : "20060222 IRM 017: Multiple Vulnerabilities in Infovista Portal SE",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16776",
          "name" : "16776",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0695",
          "name" : "ADV-2006-0695",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24894",
          "name" : "vistaportal-server-path-disclosure(24894)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "InfoVista PortalSE 2.0 Build 20087 on Solaris 8 allows remote attackers to obtain sensitive information by specifying a nonexistent server in the server field, which reveals the path in an error message."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:infovista:portalse:2.0_build_20087:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-23T23:02Z",
    "lastModifiedDate" : "2018-10-18T16:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0864",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "hauri",
            "product" : {
              "product_data" : [ {
                "product_name" : "virobot",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0_2005-08-17",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18974",
          "name" : "18974",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1015658",
          "name" : "1015658",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/425788/100/0/threaded",
          "name" : "20060222 [INetCop Security Advisory] Global Hauri Virobot cookie exploit",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16768",
          "name" : "16768",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0691",
          "name" : "ADV-2006-0691",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "http://x82.inetcop.org/h0me/adv1sor1es/INCSA.2006-0x82-028-VIROBOT.txt",
          "name" : "http://x82.inetcop.org/h0me/adv1sor1es/INCSA.2006-0x82-028-VIROBOT.txt",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24850",
          "name" : "virobot-filescan-auth-bypass(24850)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "filescan in Global Hauri ViRobot 2.0 20050817 does not verify the Cookie HTTP header, which allows remote attackers to gain administrative privileges via an arbitrary cookie value."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hauri:virobot:2.0_2005-08-17:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-23T23:02Z",
    "lastModifiedDate" : "2018-10-18T16:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0865",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "punbb",
            "product" : {
              "product_data" : [ {
                "product_name" : "punbb",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0_alpha",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0_beta1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0_beta1a",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0_beta2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0_beta3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0_rc1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0_rc2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.10",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.neosecurityteam.net/advisories/Advisory-15.txt",
          "name" : "http://www.neosecurityteam.net/advisories/Advisory-15.txt",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/425630/100/0/threaded",
          "name" : "20060219 PunBB 1.2.10 Multiple DoS Vulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24837",
          "name" : "punbb-register-ip-dos(24837)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "PunBB 1.2.10 and earlier allows remote attackers to cause a denial of service (resource consumption) by registering many user accounts quickly."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:punbb:punbb:1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:punbb:punbb:1.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:punbb:punbb:1.0_alpha:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:punbb:punbb:1.0_beta1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:punbb:punbb:1.0_beta1a:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:punbb:punbb:1.0_beta2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:punbb:punbb:1.0_beta3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:punbb:punbb:1.0_rc1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:punbb:punbb:1.0_rc2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:punbb:punbb:1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:punbb:punbb:1.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:punbb:punbb:1.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:punbb:punbb:1.1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:punbb:punbb:1.1.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:punbb:punbb:1.1.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:punbb:punbb:1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:punbb:punbb:1.2.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:punbb:punbb:1.2.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:punbb:punbb:1.2.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:punbb:punbb:1.2.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:punbb:punbb:1.2.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:punbb:punbb:1.2.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:punbb:punbb:1.2.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:punbb:punbb:1.2.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:punbb:punbb:1.2.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:punbb:punbb:1.2.10:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-23T23:02Z",
    "lastModifiedDate" : "2018-10-18T16:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0866",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "punbb",
            "product" : {
              "product_data" : [ {
                "product_name" : "punbb",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0_alpha",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0_beta1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0_beta1a",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0_beta2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0_beta3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0_rc1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0_rc2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.10",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.neosecurityteam.net/advisories/Advisory-15.txt",
          "name" : "http://www.neosecurityteam.net/advisories/Advisory-15.txt",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/425630/100/0/threaded",
          "name" : "20060219 PunBB 1.2.10 Multiple DoS Vulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24838",
          "name" : "punbb-login-bruteforce(24838)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "PunBB 1.2.10 and earlier allows remote attackers to conduct brute force guessing attacks for an account's password, which may be as short as 4 characters."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:punbb:punbb:1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:punbb:punbb:1.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:punbb:punbb:1.0_alpha:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:punbb:punbb:1.0_beta1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:punbb:punbb:1.0_beta1a:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:punbb:punbb:1.0_beta2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:punbb:punbb:1.0_beta3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:punbb:punbb:1.0_rc1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:punbb:punbb:1.0_rc2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:punbb:punbb:1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:punbb:punbb:1.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:punbb:punbb:1.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:punbb:punbb:1.1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:punbb:punbb:1.1.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:punbb:punbb:1.1.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:punbb:punbb:1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:punbb:punbb:1.2.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:punbb:punbb:1.2.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:punbb:punbb:1.2.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:punbb:punbb:1.2.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:punbb:punbb:1.2.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:punbb:punbb:1.2.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:punbb:punbb:1.2.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:punbb:punbb:1.2.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:punbb:punbb:1.2.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:punbb:punbb:1.2.10:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-23T23:02Z",
    "lastModifiedDate" : "2018-10-18T16:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0867",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "south_river",
            "product" : {
              "product_data" : [ {
                "product_name" : "webdrive",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.08_build_1131",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/archive/1/425785/100/0/threaded",
          "name" : "20060222 South River WebDrive Buffer Overflow Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24903",
          "name" : "webdrive-name-bo(24903)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Buffer overflow in certain versions of South River (aka SRT) WebDrive, possibly version 6.08 build 1131 and version 8, allows remote attackers to cause a denial of service (application crash and persistent erratic behavior) via a long string in the name entry field."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:south_river:webdrive:6.08_build_1131:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:south_river:webdrive:8:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-23T23:02Z",
    "lastModifiedDate" : "2018-10-18T16:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0868",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "pear",
            "product" : {
              "product_data" : [ {
                "product_name" : "xml_rpc",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.0rc1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.0rc2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.0rc3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.0rc4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.0rc5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.0rc6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.0rc7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.0rc1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.0rc2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.0rc3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://pear.php.net/package/Auth/download/1.2.4",
          "name" : "http://pear.php.net/package/Auth/download/1.2.4",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://pear.php.net/package/Auth/download/1.3.0r4",
          "name" : "http://pear.php.net/package/Auth/download/1.3.0r4",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://secunia.com/advisories/19008",
          "name" : "19008",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/19301",
          "name" : "19301",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1015666",
          "name" : "1015666",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.gentoo.org/security/en/glsa/glsa-200603-13.xml",
          "name" : "GLSA-200603-13",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/425796/100/0/threaded",
          "name" : "20060222 Multiple Injection Vulnerabilities in PHP PEAR::Auth Module",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16758",
          "name" : "16758",
          "refsource" : "BID",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0696",
          "name" : "ADV-2006-0696",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24854",
          "name" : "auth-multiple-injections(24854)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple unspecified injection vulnerabilities in unspecified Auth Container back ends for PEAR::Auth before 1.2.4, and 1.3.x before 1.3.0r4, allow remote attackers to \"falsify authentication credentials,\" related to the \"underlying storage containers.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pear:xml_rpc:1.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pear:xml_rpc:1.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pear:xml_rpc:1.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pear:xml_rpc:1.1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pear:xml_rpc:1.2.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pear:xml_rpc:1.2.0rc1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pear:xml_rpc:1.2.0rc2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pear:xml_rpc:1.2.0rc3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pear:xml_rpc:1.2.0rc4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pear:xml_rpc:1.2.0rc5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pear:xml_rpc:1.2.0rc6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pear:xml_rpc:1.2.0rc7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pear:xml_rpc:1.2.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pear:xml_rpc:1.2.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pear:xml_rpc:1.3.0rc1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pear:xml_rpc:1.3.0rc2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pear:xml_rpc:1.3.0rc3:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-23T23:02Z",
    "lastModifiedDate" : "2018-10-18T16:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0869",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "pear",
            "product" : {
              "product_data" : [ {
                "product_name" : "pear_liveuser",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.5.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.6.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.10.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.11.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.11.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.12.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.13.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.13.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.13.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.13.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.14.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.15.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.15.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.16.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.16.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.16.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.16.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.16.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.16.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.16.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.16.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.16.8",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://pear.php.net/package/LiveUser/download/",
          "name" : "http://pear.php.net/package/LiveUser/download/",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://securityreason.com/securityalert/466",
          "name" : "466",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1015659",
          "name" : "1015659",
          "refsource" : "SECTRACK",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.gulftech.org/?node=research&article_id=00103-02212006",
          "name" : "http://www.gulftech.org/?node=research&article_id=00103-02212006",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/425711/100/0/threaded",
          "name" : "20060221 PEAR LiveUser File Access Vulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16761",
          "name" : "16761",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0697",
          "name" : "ADV-2006-0697",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24852",
          "name" : "liveuser-liveuser-file-access(24852)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24853",
          "name" : "liveuser-liveuser-file-deletion(24853)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Directory traversal vulnerability in the \"remember me\" feature in liveuser.php in PHP Extension and Application Repository (PEAR) LiveUser 0.16.8 and earlier allows remote attackers to determine file existence, and possibly delete arbitrary files with short pathnames or possibly read arbitrary files, via a .. (dot dot) in the store_id value of a cookie."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pear:pear_liveuser:0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pear:pear_liveuser:0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pear:pear_liveuser:0.5.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pear:pear_liveuser:0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pear:pear_liveuser:0.6.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pear:pear_liveuser:0.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pear:pear_liveuser:0.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pear:pear_liveuser:0.8.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pear:pear_liveuser:0.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pear:pear_liveuser:0.10.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pear:pear_liveuser:0.11.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pear:pear_liveuser:0.11.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pear:pear_liveuser:0.12.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pear:pear_liveuser:0.13.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pear:pear_liveuser:0.13.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pear:pear_liveuser:0.13.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pear:pear_liveuser:0.13.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pear:pear_liveuser:0.14.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pear:pear_liveuser:0.15.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pear:pear_liveuser:0.15.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pear:pear_liveuser:0.16.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pear:pear_liveuser:0.16.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pear:pear_liveuser:0.16.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pear:pear_liveuser:0.16.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pear:pear_liveuser:0.16.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pear:pear_liveuser:0.16.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pear:pear_liveuser:0.16.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pear:pear_liveuser:0.16.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pear:pear_liveuser:0.16.8:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 6.4
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-23T23:02Z",
    "lastModifiedDate" : "2018-10-18T16:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0870",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "mini-nuke",
            "product" : {
              "product_data" : [ {
                "product_name" : "mini-nuke_cms",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.8.2",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18439",
          "name" : "18439",
          "refsource" : "SECUNIA",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://www.nukedx.com/?viewdoc=9",
          "name" : "http://www.nukedx.com/?viewdoc=9",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.osvdb.org/23438",
          "name" : "23438",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/425599/100/0/threaded",
          "name" : "20060220 MiniNuke CMS System all versions (pages.asp) SQL Injection",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/428361/100/0/threaded",
          "name" : "20060321 Mini-Nuke<=1.8.2 SQL injection (6)",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/431602/100/0/threaded",
          "name" : "20060420 Mini-NUKE v2.3<<--- SQL Injection",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/431714/100/0/threaded",
          "name" : "20060421 Re: Mini-NUKE v2.3<<--- SQL Injection",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16730",
          "name" : "16730",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/17636",
          "name" : "17636",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24803",
          "name" : "mininuke-pages-sql-injection(24803)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in pages.asp in Mini-Nuke CMS System 1.8.2 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.  NOTE: version 2.3 was later reported to be vulnerable as well."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mini-nuke:mini-nuke_cms:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.8.2"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-23T23:02Z",
    "lastModifiedDate" : "2018-10-18T16:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0871",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "mambo",
            "product" : {
              "product_data" : [ {
                "product_name" : "mambo",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.5.3h",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-22"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://archives.neohapsis.com/archives/bugtraq/2006-02/0463.html",
          "name" : "20060224 Mambo Multiple Vulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18935",
          "name" : "18935",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/493",
          "name" : "493",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://source.mambo-foundation.org/view/news/Announcements/Security_Patch_Released/",
          "name" : "http://source.mambo-foundation.org/view/news/Announcements/Security_Patch_Released/",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.gulftech.org/?node=research&article_id=00104-02242006",
          "name" : "http://www.gulftech.org/?node=research&article_id=00104-02242006",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/23505",
          "name" : "23505",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0719",
          "name" : "ADV-2006-0719",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Directory traversal vulnerability in the _setTemplate function in Mambo 4.5.3, 4.5.3h, and possibly earlier versions allows remote attackers to read and include arbitrary files via the mos_change_template parameter.  NOTE: CVE-2006-1794 has been assigned to the SQL injection vector."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mambo:mambo:4.5.3h:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mambo:mambo:4.5.3h:h:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 6.4
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-24T11:02Z",
    "lastModifiedDate" : "2011-03-07T05:00Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0872",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "coppermine",
            "product" : {
              "product_data" : [ {
                "product_name" : "coppermine_photo_gallery",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.4.3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://coppermine-gallery.net/forum/index.php?topic=28062.0",
          "name" : "http://coppermine-gallery.net/forum/index.php?topic=28062.0",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://retrogod.altervista.org/cpg_143_adv.html",
          "name" : "http://retrogod.altervista.org/cpg_143_adv.html",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://retrogod.altervista.org/cpg_143_incl_xpl.html",
          "name" : "http://retrogod.altervista.org/cpg_143_incl_xpl.html",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://secunia.com/advisories/18941",
          "name" : "18941",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1015646",
          "name" : "1015646",
          "refsource" : "SECTRACK",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/425387",
          "name" : "20060218 Coppermine Photo Gallery <=1.4.3 remote code execution",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16718",
          "name" : "16718",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0669",
          "name" : "ADV-2006-0669",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24814",
          "name" : "coppermine-init-file-include(24814)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Directory traversal vulnerability in init.inc.php in Coppermine Photo Gallery 1.4.3 and earlier allows remote attackers to include arbitrary files via a .. (dot dot) sequence and trailing NULL (%00) byte in the lang parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:coppermine:coppermine_photo_gallery:1.4.3:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-24T11:02Z",
    "lastModifiedDate" : "2017-07-20T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0873",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "coppermine",
            "product" : {
              "product_data" : [ {
                "product_name" : "coppermine_photo_gallery",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.4.3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://coppermine-gallery.net/forum/index.php?topic=28062.0",
          "name" : "http://coppermine-gallery.net/forum/index.php?topic=28062.0",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://retrogod.altervista.org/cpg_143_adv.html",
          "name" : "http://retrogod.altervista.org/cpg_143_adv.html",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://secunia.com/advisories/18941",
          "name" : "18941",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1015646",
          "name" : "1015646",
          "refsource" : "SECTRACK",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/425387",
          "name" : "20060218 Coppermine Photo Gallery <=1.4.3 remote code execution",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16718",
          "name" : "16718",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0669",
          "name" : "ADV-2006-0669",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24816",
          "name" : "coppermine-showdoc-file-include(24816)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Absolute path traversal vulnerability in docs/showdocs.php in Coppermine Photo Gallery 1.4.3 and earlier allows remote attackers to include arbitrary files via the f parameter, and possibly remote files using UNC share pathnames."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:coppermine:coppermine_photo_gallery:1.4.3:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-24T11:02Z",
    "lastModifiedDate" : "2017-07-20T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0874",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "intensive_point",
            "product" : {
              "product_data" : [ {
                "product_name" : "iuser_ecommerce",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.1",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/19003",
          "name" : "19003",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.intensivepoint.com/iuser-document.shtml",
          "name" : "http://www.intensivepoint.com/iuser-document.shtml",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16787",
          "name" : "16787",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24906",
          "name" : "iuser-ecommerce-undisclosed(24906)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple unspecified vulnerabilities in Intensive Point iUser Ecommerce before 2.2 have unspecified vectors and impact, as addressed by \"Urgent secure fixes\".  NOTE: this might be a duplicate of CVE-2006-0854, but the vendor announcement for this issue (from January 8, 2005) is too vague to be sure, and CVE-2006-0854 does not provide version information."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:intensive_point:iuser_ecommerce:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "2.1"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "acInsufInfo" : true,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-24T11:02Z",
    "lastModifiedDate" : "2017-07-20T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0875",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "runcms",
            "product" : {
              "product_data" : [ {
                "product_name" : "runcms",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1a",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3a",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3a2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3a5",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://kapda.ir/advisory-267.html",
          "name" : "http://kapda.ir/advisory-267.html",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/18997",
          "name" : "18997",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1015663",
          "name" : "1015663",
          "refsource" : "SECTRACK",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.osvdb.org/23388",
          "name" : "23388",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/425775/100/0/threaded",
          "name" : "20060222 [KAPDA::#27] - Runcms 1.x Cross_Site_Scripting vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16769",
          "name" : "16769",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0694",
          "name" : "ADV-2006-0694",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24871",
          "name" : "runcms-ratefile-xss(24871)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting vulnerability in ratefile.php in RunCMS 1.3a5 allows remote attackers to inject arbitrary web script or HTML via the lid parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:runcms:runcms:1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:runcms:runcms:1.1a:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:runcms:runcms:1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:runcms:runcms:1.3a:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:runcms:runcms:1.3a2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:runcms:runcms:1.3a5:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-24T11:02Z",
    "lastModifiedDate" : "2018-10-18T16:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0876",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "popfile",
            "product" : {
              "product_data" : [ {
                "product_name" : "popfile",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.18.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.19.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.20.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.21.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://popfile.sourceforge.net/cgi-bin/wiki.pl?ReleaseNotes/0.22.4",
          "name" : "http://popfile.sourceforge.net/cgi-bin/wiki.pl?ReleaseNotes/0.22.4",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18975",
          "name" : "18975",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/20205",
          "name" : "20205",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2006/dsa-1061",
          "name" : "DSA-1061",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16792",
          "name" : "16792",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0698",
          "name" : "ADV-2006-0698",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "POPFile before 0.22.4 allows remote attackers to cause a denial of service (application crash) via unspecified vectors involving character sets within e-mail messages."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:popfile:popfile:0.18.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:popfile:popfile:0.19.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:popfile:popfile:0.20.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:popfile:popfile:0.21.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-24T11:02Z",
    "lastModifiedDate" : "2011-03-08T02:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0877",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "easy_forum",
            "product" : {
              "product_data" : [ {
                "product_name" : "easy_forum",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.5",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://evuln.com/vulns/85/summary.html",
          "name" : "http://evuln.com/vulns/85/summary.html",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://hot-things.net/forum/show.php?f=2&topic=20060224080919",
          "name" : "http://hot-things.net/forum/show.php?f=2&topic=20060224080919",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18996",
          "name" : "18996",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/23430",
          "name" : "23430",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/426760/100/0/threaded",
          "name" : "20060304 [eVuln] Easy Forum XSS Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16958",
          "name" : "16958",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0706",
          "name" : "ADV-2006-0706",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24831",
          "name" : "easyforum-join-xss(24831)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting vulnerability in Easy Forum 2.5 allows remote attackers to inject arbitrary web script or HTML via the image variable."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:easy_forum:easy_forum:2.5:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-24T11:02Z",
    "lastModifiedDate" : "2018-10-18T16:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0878",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "phpoutsourcing",
            "product" : {
              "product_data" : [ {
                "product_name" : "noahs_classifieds",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://securitytracker.com/id?1015667",
          "name" : "1015667",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.kapda.ir/advisory-268.html",
          "name" : "http://www.kapda.ir/advisory-268.html",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/425783/100/0/threaded",
          "name" : "20060222 [KAPDA::#29]Noah's classifieds multiple vulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0703",
          "name" : "ADV-2006-0703",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24898",
          "name" : "noahs-category-path-disclosure(24898)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Noah's Classifieds 1.3 allows remote attackers to obtain the installation path via a direct request to include files, as demonstrated by classifieds/gorum/category.php."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:phpoutsourcing:noahs_classifieds:1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:phpoutsourcing:noahs_classifieds:1.3:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-24T11:02Z",
    "lastModifiedDate" : "2018-10-18T16:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0879",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "phpoutsourcing",
            "product" : {
              "product_data" : [ {
                "product_name" : "noahs_classifieds",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://securitytracker.com/id?1015667",
          "name" : "1015667",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.kapda.ir/advisory-268.html",
          "name" : "http://www.kapda.ir/advisory-268.html",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/425783/100/0/threaded",
          "name" : "20060222 [KAPDA::#29]Noah's classifieds multiple vulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16773",
          "name" : "16773",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0703",
          "name" : "ADV-2006-0703",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24896",
          "name" : "noahs-search-sql-injection(24896)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in the search tool in Noah's Classifieds 1.3 allows remote attackers to execute arbitrary SQL commands via unspecified attack vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:phpoutsourcing:noahs_classifieds:1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:phpoutsourcing:noahs_classifieds:1.3:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-24T11:02Z",
    "lastModifiedDate" : "2018-10-18T16:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0880",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "phpoutsourcing",
            "product" : {
              "product_data" : [ {
                "product_name" : "noahs_classifieds",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://securitytracker.com/id?1015667",
          "name" : "1015667",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.kapda.ir/advisory-268.html",
          "name" : "http://www.kapda.ir/advisory-268.html",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/425783/100/0/threaded",
          "name" : "20060222 [KAPDA::#29]Noah's classifieds multiple vulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16772",
          "name" : "16772",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0703",
          "name" : "ADV-2006-0703",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24895",
          "name" : "noahs-indexphp-xss(24895)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple cross-site scripting (XSS) vulnerabilities in index.php in Noah's Classifieds 1.3 allow remote attackers to inject arbitrary web script or HTML via the (1) inf parameter; or, when register_globals is enabled, the (2) upperTemplate and (3) lowerTemplate parameters."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:phpoutsourcing:noahs_classifieds:1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:phpoutsourcing:noahs_classifieds:1.3:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-24T11:02Z",
    "lastModifiedDate" : "2018-10-18T16:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0881",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "phpoutsourcing",
            "product" : {
              "product_data" : [ {
                "product_name" : "noahs_classifieds",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://securitytracker.com/id?1015667",
          "name" : "1015667",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.kapda.ir/advisory-268.html",
          "name" : "http://www.kapda.ir/advisory-268.html",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/425783/100/0/threaded",
          "name" : "20060222 [KAPDA::#29]Noah's classifieds multiple vulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16780",
          "name" : "16780",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0703",
          "name" : "ADV-2006-0703",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24899",
          "name" : "noahs-gorumlib-file-include(24899)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple PHP remote file include vulnerabilities in gorum/gorumlib.php in Noah's Classifieds 1.3, when register_globals is enabled, allow remote attackers to include arbitrary PHP files via the (1) upperTemplate and (2) lowerTemplate parameters, as demonstrated using the lowerTemplate parameter to index.php."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:phpoutsourcing:noahs_classifieds:1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:phpoutsourcing:noahs_classifieds:1.3:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-24T11:02Z",
    "lastModifiedDate" : "2018-10-18T16:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0882",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "phpoutsourcing",
            "product" : {
              "product_data" : [ {
                "product_name" : "noahs_classifieds",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://securitytracker.com/id?1015667",
          "name" : "1015667",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.kapda.ir/advisory-268.html",
          "name" : "http://www.kapda.ir/advisory-268.html",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/425783/100/0/threaded",
          "name" : "20060222 [KAPDA::#29]Noah's classifieds multiple vulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16778",
          "name" : "16778",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0703",
          "name" : "ADV-2006-0703",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24900",
          "name" : "noahs-include-directory-traversal(24900)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Directory traversal vulnerability in include.php in Noah's Classifieds 1.3 allows remote attackers to include arbitrary local files via the otherTemplate parameter to index.php."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:phpoutsourcing:noahs_classifieds:1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:phpoutsourcing:noahs_classifieds:1.3:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-24T11:02Z",
    "lastModifiedDate" : "2018-10-18T16:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0883",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "openbsd",
            "product" : {
              "product_data" : [ {
                "product_name" : "openssh",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.8.1p1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "freebsd",
            "product" : {
              "product_data" : [ {
                "product_name" : "freebsd",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.4",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-399"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-06:09.openssh.asc",
          "name" : "FreeBSD-SA-06:09",
          "refsource" : "FREEBSD",
          "tags" : [ ]
        }, {
          "url" : "http://bugzilla.mindrot.org/show_bug.cgi?id=839",
          "name" : "http://bugzilla.mindrot.org/show_bug.cgi?id=839",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/520",
          "name" : "520",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1015706",
          "name" : "1015706",
          "refsource" : "SECTRACK",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.osvdb.org/23797",
          "name" : "23797",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16892",
          "name" : "16892",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0805",
          "name" : "ADV-2006-0805",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/25116",
          "name" : "openssh-openpam-dos(25116)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "OpenSSH on FreeBSD 5.3 and 5.4, when used with OpenPAM, does not properly handle when a forked child process terminates during PAM authentication, which allows remote attackers to cause a denial of service (client connection refusal) by connecting multiple times to the SSH server, waiting for the password prompt, then disconnecting."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openbsd:openssh:3.8.1p1:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:freebsd:freebsd:5.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:freebsd:freebsd:5.3:release:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:freebsd:freebsd:5.3:releng:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:freebsd:freebsd:5.3:stable:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:freebsd:freebsd:5.4:pre-release:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:freebsd:freebsd:5.4:release:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:freebsd:freebsd:5.4:releng:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:freebsd:freebsd:5.4:stable:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-03-07T02:02Z",
    "lastModifiedDate" : "2017-07-20T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0884",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "mozilla",
            "product" : {
              "product_data" : [ {
                "product_name" : "thunderbird",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.7.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.7.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.7.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.7",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-20"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2006.26/SCOSA-2006.26.txt",
          "name" : "SCOSA-2006.26",
          "refsource" : "SCO",
          "tags" : [ ]
        }, {
          "url" : "ftp://patches.sgi.com/support/free/security/advisories/20060404-01-U.asc",
          "name" : "20060404-01-U",
          "refsource" : "SGI",
          "tags" : [ ]
        }, {
          "url" : "http://lists.suse.com/archive/suse-security-announce/2006-Apr/0003.html",
          "name" : "SUSE-SA:2006:021",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/19721",
          "name" : "19721",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/19811",
          "name" : "19811",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/19821",
          "name" : "19821",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/19823",
          "name" : "19823",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/19863",
          "name" : "19863",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/19902",
          "name" : "19902",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/19941",
          "name" : "19941",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/19950",
          "name" : "19950",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/20051",
          "name" : "20051",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/21033",
          "name" : "21033",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/21622",
          "name" : "21622",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/22065",
          "name" : "22065",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1015665",
          "name" : "1015665",
          "refsource" : "SECTRACK",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://sunsolve.sun.com/search/document.do?assetkey=1-26-102550-1",
          "name" : "102550",
          "refsource" : "SUNALERT",
          "tags" : [ ]
        }, {
          "url" : "http://sunsolve.sun.com/search/document.do?assetkey=1-26-228526-1",
          "name" : "228526",
          "refsource" : "SUNALERT",
          "tags" : [ ]
        }, {
          "url" : "http://support.avaya.com/elmodocs2/security/ASA-2006-205.htm",
          "name" : "http://support.avaya.com/elmodocs2/security/ASA-2006-205.htm",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2006/dsa-1046",
          "name" : "DSA-1046",
          "refsource" : "DEBIAN",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.debian.org/security/2006/dsa-1051",
          "name" : "DSA-1051",
          "refsource" : "DEBIAN",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.gentoo.org/security/en/glsa/glsa-200604-18.xml",
          "name" : "GLSA-200604-18",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://www.gentoo.org/security/en/glsa/glsa-200605-09.xml",
          "name" : "GLSA-200605-09",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDKSA-2006:052",
          "name" : "MDKSA-2006:052",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDKSA-2006:076",
          "name" : "MDKSA-2006:076",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDKSA-2006:078",
          "name" : "MDKSA-2006:078",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.mozilla.org/security/announce/2006/mfsa2006-21.html",
          "name" : "http://www.mozilla.org/security/announce/2006/mfsa2006-21.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.novell.com/linux/security/advisories/2006_04_25.html",
          "name" : "SUSE-SA:2006:022",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/23653",
          "name" : "23653",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2006-0329.html",
          "name" : "RHSA-2006:0329",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2006-0330.html",
          "name" : "RHSA-2006:0330",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/425786/100/0/threaded",
          "name" : "20060222 Mozilla Thunderbird : Remote Code Execution & Denial of Service",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/436296/100/0/threaded",
          "name" : "FLSA:189137-1",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/438730/100/0/threaded",
          "name" : "HPSBUX02122",
          "refsource" : "HP",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/446657/100/200/threaded",
          "name" : "SSRT061236",
          "refsource" : "HP",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16770",
          "name" : "16770",
          "refsource" : "BID",
          "tags" : [ "Exploit", "Patch" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/3749",
          "name" : "ADV-2006-3749",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/25983",
          "name" : "mozilla-inline-fwd-code-execution(25983)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10782",
          "name" : "oval:org.mitre.oval:def:10782",
          "refsource" : "OVAL",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2024",
          "name" : "oval:org.mitre.oval:def:2024",
          "refsource" : "OVAL",
          "tags" : [ ]
        }, {
          "url" : "https://usn.ubuntu.com/276-1/",
          "name" : "USN-276-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The WYSIWYG rendering engine (\"rich mail\" editor) in Mozilla Thunderbird 1.0.7 and earlier allows user-assisted attackers to bypass javascript security settings and obtain sensitive information or cause a crash via an e-mail containing a javascript URI in the SRC attribute of an IFRAME tag, which is executed when the user edits the e-mail."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:thunderbird:0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:thunderbird:0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:thunderbird:0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:thunderbird:0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:thunderbird:0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:thunderbird:0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:thunderbird:0.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:thunderbird:0.7.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:thunderbird:0.7.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:thunderbird:0.7.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:thunderbird:0.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:thunderbird:0.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:thunderbird:1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:thunderbird:1.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:thunderbird:1.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:thunderbird:1.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:thunderbird:1.0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.0.7"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2006-02-24T22:02Z",
    "lastModifiedDate" : "2018-10-18T16:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0885",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "cutephp",
            "product" : {
              "product_data" : [ {
                "product_name" : "cutenews",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.4.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://myimei.com/security/2006-02-20/cutenews141addcommentforprotectedusernamesxss-attack.html",
          "name" : "http://myimei.com/security/2006-02-20/cutenews141addcommentforprotectedusernamesxss-attack.html",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18981",
          "name" : "18981",
          "refsource" : "SECUNIA",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/23400",
          "name" : "23400",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/425583",
          "name" : "20060221 [myimei]CuteNews1.4.1~ Add Comment For Protected UserNames~ XSS Attack",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16740",
          "name" : "16740",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0685",
          "name" : "ADV-2006-0685",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24835",
          "name" : "cutenews-shownews-xss(24835)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in show_news.php in CuteNews 1.4.1 allows remote attackers to inject arbitrary web script or HTML via the show parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cutephp:cutenews:1.4.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-25T11:02Z",
    "lastModifiedDate" : "2017-07-20T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0886",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "dev",
            "product" : {
              "product_data" : [ {
                "product_name" : "dev_web_management_system",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.5",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18714",
          "name" : "18714",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/23468",
          "name" : "23468",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16812",
          "name" : "16812",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0723",
          "name" : "ADV-2006-0723",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24875",
          "name" : "dev-cityregion-xss(24875)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in register.php in DEV web management system 1.5 allows remote attackers to inject arbitrary web script or HTML via the \"City/Region\" field (mesto variable).  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:dev:dev_web_management_system:1.5:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-25T11:02Z",
    "lastModifiedDate" : "2017-07-20T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0887",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "phplib_team",
            "product" : {
              "product_data" : [ {
                "product_name" : "phplib",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.4",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-94"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/16902",
          "name" : "16902",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1016123",
          "name" : "1016123",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://sourceforge.net/project/shownotes.php?group_id=31885&release_id=396091",
          "name" : "http://sourceforge.net/project/shownotes.php?group_id=31885&release_id=396091",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.gulftech.org/?node=research&article_id=00107-03052006",
          "name" : "http://www.gulftech.org/?node=research&article_id=00107-03052006",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/23466",
          "name" : "23466",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16801",
          "name" : "16801",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0720",
          "name" : "ADV-2006-0720",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24873",
          "name" : "phplib-code-execution(24873)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Eval injection vulnerability in sessions.inc in PHP Base Library (PHPLib) before 7.4a, when index.php3 from the PHPLib distribution is available on the server, allows remote attackers to execute arbitrary PHP code by including a base64-encoded representation of the code in a cookie.  NOTE: this description was significantly updated on 20060605 to reflect new details after an initial vague advisory."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:phplib_team:phplib:7.4:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-25T11:02Z",
    "lastModifiedDate" : "2017-07-20T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0888",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "invision_power_services",
            "product" : {
              "product_data" : [ {
                "product_name" : "invision_power_board",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/16616",
          "name" : "16616",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/1489",
          "name" : "1489",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "index.php in Invision Power Board (IPB) 2.0.1, with Code Confirmation disabled, allows remote attackers to cause an unspecified denial of service by registering a large number of users."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:invision_power_services:invision_power_board:2.0.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:H/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "HIGH",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 2.6
        },
        "severity" : "LOW",
        "exploitabilityScore" : 4.9,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-25T11:02Z",
    "lastModifiedDate" : "2017-10-19T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0889",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "brown_bear_software",
            "product" : {
              "product_data" : [ {
                "product_name" : "calcium",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.10.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/19007",
          "name" : "19007",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/23471",
          "name" : "23471",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16851",
          "name" : "16851",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0724",
          "name" : "ADV-2006-0724",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24907",
          "name" : "calcium-eventtext-xss(24907)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in Calcium 3.10.1 allows remote attackers to inject arbitrary web script or HTML via the EventText parameter.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:brown_bear_software:calcium:3.10.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-25T11:02Z",
    "lastModifiedDate" : "2017-07-20T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0890",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "speedproject",
            "product" : {
              "product_data" : [ {
                "product_name" : "speedcommander",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11.01_build4450",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "squeez",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.1",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "zipstar",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/19006",
          "name" : "19006",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/23465",
          "name" : "23465",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/425973/100/0/threaded",
          "name" : "20060224 SpeedCommander 11.0 & ZipStar 5.1 & Squeez 5.1 Directory traversal",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16807",
          "name" : "16807",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0731",
          "name" : "ADV-2006-0731",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24909",
          "name" : "speedproject-zip-jar-directory-traversal(24909)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Directory traversal vulnerability in SpeedProject Squeez 5.1, as used in (1) ZipStar 5.1 and (2) SpeedCommander 11.01.4450, allows remote attackers to overwrite arbitrary files via unspecified manipulations in a (1) JAR or (2) ZIP archive."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:speedproject:speedcommander:11.01_build4450:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:speedproject:squeez:5.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:speedproject:zipstar:5.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-25T11:02Z",
    "lastModifiedDate" : "2018-10-18T16:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0891",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "nocc",
            "product" : {
              "product_data" : [ {
                "product_name" : "nocc",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://archives.neohapsis.com/archives/bugtraq/2006-02/0418.html",
          "name" : "20060223 NOCC Webmail <= 1.0 multiple vulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://retrogod.altervista.org/noccw_10_incl_xpl.html",
          "name" : "http://retrogod.altervista.org/noccw_10_incl_xpl.html",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/16921",
          "name" : "16921",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1015671",
          "name" : "1015671",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/23416",
          "name" : "23416",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/23417",
          "name" : "23417",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/23418",
          "name" : "23418",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/23419",
          "name" : "23419",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16793",
          "name" : "16793",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24934",
          "name" : "nocc-index-file-include(24934)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple directory traversal vulnerabilities in NOCC Webmail 1.0 allow remote attackers to include arbitrary files via .. (dot dot) sequences and a trailing NULL (%00) byte in (1) the _SESSION['nocc_theme'] parameter in (a) html/footer.php; and (2) the lang and (3) theme parameters and the (4) Accept-Language HTTP header field, when force_default_lang is disabled, in (b) index.php, as demonstrated by injecting PHP code into a profile and accessing it using the lang parameter in index.php."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:nocc:nocc:1.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-25T11:02Z",
    "lastModifiedDate" : "2017-07-20T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0892",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "nocc",
            "product" : {
              "product_data" : [ {
                "product_name" : "nocc",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://archives.neohapsis.com/archives/bugtraq/2006-02/0418.html",
          "name" : "20060223 NOCC Webmail <= 1.0 multiple vulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://retrogod.altervista.org/noccw_10_incl_xpl.html",
          "name" : "http://retrogod.altervista.org/noccw_10_incl_xpl.html",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/16921",
          "name" : "16921",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1015671",
          "name" : "1015671",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/23420",
          "name" : "23420",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16793",
          "name" : "16793",
          "refsource" : "BID",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "NOCC Webmail 1.0 stores e-mail attachments in temporary files with predictable filenames, which makes it easier for remote attackers to execute arbitrary code by accessing the e-mail attachment via directory traversal vulnerabilities."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:nocc:nocc:1.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-25T11:02Z",
    "lastModifiedDate" : "2008-09-05T21:00Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0893",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "nocc",
            "product" : {
              "product_data" : [ {
                "product_name" : "nocc",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://archives.neohapsis.com/archives/bugtraq/2006-02/0418.html",
          "name" : "20060223 NOCC Webmail <= 1.0 multiple vulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://retrogod.altervista.org/noccw_10_incl_xpl.html",
          "name" : "http://retrogod.altervista.org/noccw_10_incl_xpl.html",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/16921",
          "name" : "16921",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1015671",
          "name" : "1015671",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/23420",
          "name" : "23420",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/23422",
          "name" : "23422",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16793",
          "name" : "16793",
          "refsource" : "BID",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "NOCC Webmail 1.0 allows remote attackers to obtain sensitive information via a direct request to (1) the profiles directory, which leaks e-mail addresses contained in filenames of profiles, and (2) the tmp directory, which lists names of uploaded attachments."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:nocc:nocc:1.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-25T11:02Z",
    "lastModifiedDate" : "2008-09-05T21:00Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0894",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "nocc",
            "product" : {
              "product_data" : [ {
                "product_name" : "nocc",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://archives.neohapsis.com/archives/bugtraq/2006-02/0418.html",
          "name" : "20060223 NOCC Webmail <= 1.0 multiple vulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://retrogod.altervista.org/noccw_10_incl_xpl.html",
          "name" : "http://retrogod.altervista.org/noccw_10_incl_xpl.html",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/16921",
          "name" : "16921",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1015671",
          "name" : "1015671",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/23423",
          "name" : "23423",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/23424",
          "name" : "23424",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/23425",
          "name" : "23425",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/23426",
          "name" : "23426",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/23427",
          "name" : "23427",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16793",
          "name" : "16793",
          "refsource" : "BID",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple cross-site scripting (XSS) vulnerabilities in NOCC Webmail 1.0 allow remote attackers to inject arbitrary web script or HTML via (1) the html_error_occurred parameter in error.php, (2) html_filter_select parameter in filter_prefs.php, (3) html_no_mail parameter in no_mail.php, the (4) page_line, (5) prev, and (6) next parameters in html_bottom_table.php, and the (7) _SESSION['nocc_theme'] parameter in footer.php."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:nocc:nocc:1.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-25T11:02Z",
    "lastModifiedDate" : "2008-09-05T21:00Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0895",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "nocc",
            "product" : {
              "product_data" : [ {
                "product_name" : "nocc",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://archives.neohapsis.com/archives/bugtraq/2006-02/0418.html",
          "name" : "20060223 NOCC Webmail <= 1.0 multiple vulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://retrogod.altervista.org/noccw_10_incl_xpl.html",
          "name" : "http://retrogod.altervista.org/noccw_10_incl_xpl.html",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/16921",
          "name" : "16921",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/478",
          "name" : "478",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1015671",
          "name" : "1015671",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16793",
          "name" : "16793",
          "refsource" : "BID",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "NOCC Webmail 1.0 allows remote attackers to obtain the installation path via a direct request to html/header.php."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:nocc:nocc:1.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-25T11:02Z",
    "lastModifiedDate" : "2008-09-05T21:00Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0896",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "simple_machines",
            "product" : {
              "product_data" : [ {
                "product_name" : "simple_machines_forum",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0.6",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://attrition.org/pipermail/vim/2006-April/000682.html",
          "name" : "20060410 VEndor ACK: Simple Machines Forum Register.php X-Forwarded-For XSS",
          "refsource" : "VIM",
          "tags" : [ ]
        }, {
          "url" : "http://evuln.com/vulns/86/summary.html",
          "name" : "http://evuln.com/vulns/86/summary.html",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/19004",
          "name" : "19004",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/545",
          "name" : "545",
          "refsource" : "SREASON",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/23480",
          "name" : "23480",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/426824/100/0/threaded",
          "name" : "20060306 [eVuln] Simple Machines Forum - SMF 'X-Forwarded-For' XSS Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16841",
          "name" : "16841",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.simplemachines.org/community/index.php?topic=78841.0",
          "name" : "http://www.simplemachines.org/community/index.php?topic=78841.0",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0726",
          "name" : "ADV-2006-0726",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24915",
          "name" : "smf-register-xss(24915)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in Sources/Register.php in Simple Machine Forum (SMF) 1.0.6 allows remote attackers to inject arbitrary web script or HTML via the X-Forwarded-For HTTP header field."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:simple_machines:simple_machines_forum:1.0.6:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-25T11:02Z",
    "lastModifiedDate" : "2018-10-18T16:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0897",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "virtual_communication_services",
            "product" : {
              "product_data" : [ {
                "product_name" : "vpmi_enterprise",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18842",
          "name" : "18842",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.attrition.org/pipermail/vim/2006-March/000598.html",
          "name" : "20060310 vendor dispute: VCS",
          "refsource" : "VIM",
          "tags" : [ ]
        }, {
          "url" : "http://www.attrition.org/pipermail/vim/2006-March/000599.html",
          "name" : "20060310 Re: vendor dispute: VCS",
          "refsource" : "VIM",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/23479",
          "name" : "23479",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16798",
          "name" : "16798",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0725",
          "name" : "ADV-2006-0725",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24885",
          "name" : "vpmi-servicerequests-sql-injection(24885)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "** DISPUTED **  SQL injection vulnerability in VCS Virtual Program Management Intranet (VPMi) Enterprise 3.3 allows remote attackers to execute arbitrary SQL commands via the UpdateID0 parameter to Service_Requests.asp.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.  NOTE: the vendor has disputed this issue, saying that \"[we] have a behind the scenes complex state management system that uses a combination of keys placed in JavaScript and Session State (server side) that protects against the type of SQL injection you describe.  We have tested for many of the cases and have not found it to be an issue.\"  Further investigation suggests that the original researcher might have triggered errors using invalid field values, which is not proof of SQL injection; however, the vendor did not receive a response from the original researcher."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:virtual_communication_services:vpmi_enterprise:3.3:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-25T11:02Z",
    "lastModifiedDate" : "2017-07-20T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0898",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "lincoln_d._stein",
            "product" : {
              "product_data" : [ {
                "product_name" : "crypt_cbc",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.00",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.20",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.21",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.22",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.24",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.25",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.00",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.01",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.02",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.03",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.04",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.05",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.07",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.08",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.09",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.16",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://rhn.redhat.com/errata/RHSA-2008-0630.html",
          "name" : "RHSA-2008:0630",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18755",
          "name" : "18755",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/19187",
          "name" : "19187",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/19303",
          "name" : "19303",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/20899",
          "name" : "20899",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/31493",
          "name" : "31493",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/488",
          "name" : "488",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2006/dsa-996",
          "name" : "DSA-996",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.gentoo.org/security/en/glsa/glsa-200603-15.xml",
          "name" : "GLSA-200603-15",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "http://www.novell.com/linux/security/advisories/2006_38_security.html",
          "name" : "SUSE-SR:2006:015",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2008-0261.html",
          "name" : "RHSA-2008:0261",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/425966/100/0/threaded",
          "name" : "20060223 Vulnerability in Crypt::CBC Perl module, versions <= 2.16",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16802",
          "name" : "16802",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24954",
          "name" : "crypt-cbc-header-weak-encryption(24954)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Crypt::CBC Perl module 2.16 and earlier, when running in RandomIV mode, uses an initialization vector (IV) of 8 bytes, which results in weaker encryption when used with a cipher that requires a larger block size than 8 bytes, such as Rijndael."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:lincoln_d._stein:crypt_cbc:1.00:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:lincoln_d._stein:crypt_cbc:1.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:lincoln_d._stein:crypt_cbc:1.20:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:lincoln_d._stein:crypt_cbc:1.21:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:lincoln_d._stein:crypt_cbc:1.22:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:lincoln_d._stein:crypt_cbc:1.24:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:lincoln_d._stein:crypt_cbc:1.25:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:lincoln_d._stein:crypt_cbc:2.00:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:lincoln_d._stein:crypt_cbc:2.01:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:lincoln_d._stein:crypt_cbc:2.02:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:lincoln_d._stein:crypt_cbc:2.03:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:lincoln_d._stein:crypt_cbc:2.04:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:lincoln_d._stein:crypt_cbc:2.05:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:lincoln_d._stein:crypt_cbc:2.07:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:lincoln_d._stein:crypt_cbc:2.08:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:lincoln_d._stein:crypt_cbc:2.09:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:lincoln_d._stein:crypt_cbc:2.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:lincoln_d._stein:crypt_cbc:2.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:lincoln_d._stein:crypt_cbc:2.12:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:lincoln_d._stein:crypt_cbc:2.13:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:lincoln_d._stein:crypt_cbc:2.14:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:lincoln_d._stein:crypt_cbc:2.15:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:lincoln_d._stein:crypt_cbc:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "2.16"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:H/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "HIGH",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 2.6
        },
        "severity" : "LOW",
        "exploitabilityScore" : 4.9,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2006-02-25T11:02Z",
    "lastModifiedDate" : "2018-10-18T16:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0899",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "4images",
            "product" : {
              "product_data" : [ {
                "product_name" : "image_gallery_management_system",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.7.1",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://retrogod.altervista.org/4images_171_adv.html",
          "name" : "http://retrogod.altervista.org/4images_171_adv.html",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/19026",
          "name" : "19026",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/518",
          "name" : "518",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/23529",
          "name" : "23529",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/426468/100/0/threaded",
          "name" : "20060301 4images <=1.7.1 remote code execution",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16855",
          "name" : "16855",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0754",
          "name" : "ADV-2006-0754",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24938",
          "name" : "4images-template-file-include(24938)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/1533",
          "name" : "1533",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Directory traversal vulnerability in index.php in 4Images 1.7.1 and earlier allows remote attackers to read and include arbitrary files via \"..\" (dot dot) sequences in the template parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:4images:image_gallery_management_system:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.7.1"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-27T19:06Z",
    "lastModifiedDate" : "2018-10-18T16:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0900",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "freebsd",
            "product" : {
              "product_data" : [ {
                "product_name" : "freebsd",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-06:10.nfs.asc",
          "name" : "FreeBSD-SA-06:10",
          "refsource" : "FREEBSD",
          "tags" : [ ]
        }, {
          "url" : "http://lists.immunitysec.com/pipermail/dailydave/2006-February/002982.html",
          "name" : "[Dailydave] 20060226 fun with FreeBSD kernel",
          "refsource" : "MLIST",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/19017",
          "name" : "19017",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/521",
          "name" : "521",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/23511",
          "name" : "23511",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16838",
          "name" : "16838",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24918",
          "name" : "freebsd-nfsd-kernel-dos(24918)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "nfsd in FreeBSD 6.0 kernel allows remote attackers to cause a denial of service via a crafted NFS mount request, as demonstrated by the ProtoVer NFS test suite."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:freebsd:freebsd:6.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.8
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-27T19:06Z",
    "lastModifiedDate" : "2017-07-20T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0901",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "sun",
            "product" : {
              "product_data" : [ {
                "product_name" : "solaris",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "sunos",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.8",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/19042",
          "name" : "19042",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1015680",
          "name" : "1015680",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://sunsolve.sun.com/search/document.do?assetkey=1-26-102161-1",
          "name" : "102161",
          "refsource" : "SUNALERT",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16826",
          "name" : "16826",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0756",
          "name" : "ADV-2006-0756",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24911",
          "name" : "solaris-hsfs-privilege-elevation(24911)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1628",
          "name" : "oval:org.mitre.oval:def:1628",
          "refsource" : "OVAL",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the hsfs filesystem in Solaris 8, 9, and 10 allows unspecified attackers to cause a denial of service (panic) or execute arbitrary code."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:sun:solaris:8.0:*:x86:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:sun:solaris:9.0:*:sparc:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:sun:solaris:9.0:*:x86:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:sun:solaris:10.0:*:sparc:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:sun:solaris:10.0:*:x86:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:sun:sunos:5.8:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.2
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 3.9,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-27T19:06Z",
    "lastModifiedDate" : "2018-10-30T16:25Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0903",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "mysql",
            "product" : {
              "product_data" : [ {
                "product_name" : "mysql",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.16",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.17",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "mysql",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.23",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.23.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.23.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.23.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.23.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.23.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.23.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.23.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.23.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.23.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.23.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.23.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.23.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.23.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.23.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.23.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.23.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.23.16",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.23.17",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.23.18",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.23.19",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.23.20",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.23.21",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.23.22",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.23.23",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.23.24",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.23.25",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.23.26",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.23.27",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.23.28",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.23.29",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.23.30",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.23.31",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.23.32",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.23.33",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.23.34",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.23.35",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.23.36",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.23.37",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.23.38",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.23.39",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.23.40",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.23.41",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.23.42",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.23.43",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.23.44",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.23.45",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.23.46",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.23.47",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.23.48",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.23.49",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.23.50",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.23.51",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.23.52",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.23.53",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.23.54",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.23.55",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.23.56",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.23.57",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.23.58",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.23.59",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.5a",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.16",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.17",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.18",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.19",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.20",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.21",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.23",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.24",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.25",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.26",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.27",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.16",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.17",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.18",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.19",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.18",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://archives.neohapsis.com/archives/fulldisclosure/2006-02/0653.html",
          "name" : "20060225 mysql <= 5.0.18",
          "refsource" : "FULLDISC",
          "tags" : [ ]
        }, {
          "url" : "http://bugs.mysql.com/bug.php?id=17667",
          "name" : "http://bugs.mysql.com/bug.php?id=17667",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://rst.void.ru/papers/advisory39.txt",
          "name" : "http://rst.void.ru/papers/advisory39.txt",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/19034",
          "name" : "19034",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/19502",
          "name" : "19502",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/19814",
          "name" : "19814",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/20241",
          "name" : "20241",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/20253",
          "name" : "20253",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/20333",
          "name" : "20333",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/20625",
          "name" : "20625",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/30351",
          "name" : "30351",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1015693",
          "name" : "1015693",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2006/dsa-1071",
          "name" : "DSA-1071",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2006/dsa-1073",
          "name" : "DSA-1073",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2006/dsa-1079",
          "name" : "DSA-1079",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.mandriva.com/security/advisories?name=MDKSA-2006:064",
          "name" : "MDKSA-2006:064",
          "refsource" : "MANDRIVA",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2006-0544.html",
          "name" : "RHSA-2006:0544",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2007-0083.html",
          "name" : "RHSA-2007:0083",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.redhat.com/support/errata/RHSA-2008-0364.html",
          "name" : "RHSA-2008:0364",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16850",
          "name" : "16850",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/usn-274-2",
          "name" : "USN-274-2",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0752",
          "name" : "ADV-2006-0752",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24966",
          "name" : "mysql-query-log-bypass-security(24966)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9915",
          "name" : "oval:org.mitre.oval:def:9915",
          "refsource" : "OVAL",
          "tags" : [ ]
        }, {
          "url" : "https://usn.ubuntu.com/274-1/",
          "name" : "USN-274-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "MySQL 5.0.18 and earlier allows local users to bypass logging mechanisms via SQL queries that contain the NULL character, which are not properly handled by the mysql_real_query function.  NOTE: this issue was originally reported for the mysql_query function, but the vendor states that since mysql_query expects a null character, this is not an issue for mysql_query."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mysql:mysql:4.1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mysql:mysql:4.1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mysql:mysql:4.1.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mysql:mysql:4.1.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mysql:mysql:4.1.12:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mysql:mysql:4.1.13:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mysql:mysql:4.1.14:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mysql:mysql:4.1.15:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mysql:mysql:5.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mysql:mysql:5.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mysql:mysql:5.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mysql:mysql:5.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mysql:mysql:5.0.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mysql:mysql:5.0.15:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mysql:mysql:5.0.16:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mysql:mysql:5.0.17:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:3.23:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:3.23.0:alpha:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:3.23.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:3.23.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:3.23.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:3.23.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:3.23.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:3.23.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:3.23.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:3.23.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:3.23.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:3.23.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:3.23.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:3.23.12:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:3.23.13:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:3.23.14:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:3.23.15:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:3.23.16:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:3.23.17:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:3.23.18:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:3.23.19:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:3.23.20:beta:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:3.23.21:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:3.23.22:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:3.23.23:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:3.23.24:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:3.23.25:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:3.23.26:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:3.23.27:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:3.23.28:gamma:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:3.23.29:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:3.23.30:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:3.23.31:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:3.23.32:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:3.23.33:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:3.23.34:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:3.23.35:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:3.23.36:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:3.23.37:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:3.23.38:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:3.23.39:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:3.23.40:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:3.23.41:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:3.23.42:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:3.23.43:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:3.23.44:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:3.23.45:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:3.23.46:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:3.23.47:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:3.23.48:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:3.23.49:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:3.23.50:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:3.23.51:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:3.23.52:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:3.23.53:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:3.23.54:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:3.23.55:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:3.23.56:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:3.23.57:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:3.23.58:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:3.23.59:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:4.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:4.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:4.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:4.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:4.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:4.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:4.0.5a:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:4.0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:4.0.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:4.0.7:gamma:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:4.0.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:4.0.8:gamma:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:4.0.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:4.0.9:gamma:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:4.0.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:4.0.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:4.0.11:gamma:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:4.0.12:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:4.0.13:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:4.0.14:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:4.0.15:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:4.0.16:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:4.0.17:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:4.0.18:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:4.0.19:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:4.0.20:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:4.0.21:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:4.0.23:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:4.0.24:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:4.0.25:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:4.0.26:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:4.0.27:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:4.1.0:alpha:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:4.1.2:alpha:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:4.1.3:beta:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:4.1.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:4.1.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:4.1.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:4.1.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:4.1.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:4.1.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:4.1.16:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:4.1.17:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:4.1.18:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:4.1.19:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:5.0.0:alpha:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:5.0.3:beta:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:5.0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:5.0.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:5.0.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:5.0.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:5.0.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:5.0.12:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:5.0.13:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:5.0.14:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:5.0.18:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 4.6
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 3.9,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-27T23:02Z",
    "lastModifiedDate" : "2019-12-17T20:16Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0904",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ ]
        } ]
      },
      "references" : {
        "reference_data" : [ ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "** REJECT **  DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2006. Notes: none."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ ]
    },
    "impact" : { },
    "publishedDate" : "2017-05-11T14:29Z",
    "lastModifiedDate" : "2017-05-11T14:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0905",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "freebsd",
            "product" : {
              "product_data" : [ {
                "product_name" : "freebsd",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.2.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "netbsd",
            "product" : {
              "product_data" : [ {
                "product_name" : "netbsd",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-06:11.ipsec.asc",
          "name" : "FreeBSD-SA-06:11",
          "refsource" : "FREEBSD",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2006-011.txt.asc",
          "name" : "NetBSD-SA2006-011",
          "refsource" : "NETBSD",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/19366",
          "name" : "19366",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1015809",
          "name" : "1015809",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/24068",
          "name" : "24068",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/17191",
          "name" : "17191",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/25398",
          "name" : "bsd-ipsec-replay(25398)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "A \"programming error\" in fast_ipsec in FreeBSD 4.8-RELEASE through 6.1-STABLE and NetBSD 2 through 3 does not properly update the sequence number associated with a Security Association, which allows packets to pass sequence number checks and allows remote attackers to capture IPSec packets and conduct replay attacks."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:freebsd:freebsd:4.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:freebsd:freebsd:4.8:pre-release:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:freebsd:freebsd:4.8:release_p7:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:freebsd:freebsd:4.8:releng:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:freebsd:freebsd:4.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:freebsd:freebsd:4.9:pre-release:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:freebsd:freebsd:4.9:releng:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:freebsd:freebsd:4.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:freebsd:freebsd:4.10:release:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:freebsd:freebsd:4.10:release_p8:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:freebsd:freebsd:4.10:releng:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:freebsd:freebsd:4.11:release_p3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:freebsd:freebsd:4.11:releng:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:freebsd:freebsd:4.11:stable:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:freebsd:freebsd:5.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:freebsd:freebsd:5.0:alpha:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:freebsd:freebsd:5.0:release_p14:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:freebsd:freebsd:5.0:releng:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:freebsd:freebsd:5.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:freebsd:freebsd:5.1:alpha:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:freebsd:freebsd:5.1:release:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:freebsd:freebsd:5.1:release_p5:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:freebsd:freebsd:5.1:releng:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:freebsd:freebsd:5.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:freebsd:freebsd:5.2.1:release:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:freebsd:freebsd:5.2.1:releng:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:freebsd:freebsd:5.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:freebsd:freebsd:5.3:release:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:freebsd:freebsd:5.3:releng:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:freebsd:freebsd:5.3:stable:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:freebsd:freebsd:5.4:pre-release:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:freebsd:freebsd:5.4:release:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:freebsd:freebsd:5.4:releng:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:freebsd:freebsd:5.4:stable:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:freebsd:freebsd:6.0:release:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:freebsd:freebsd:6.0:stable:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:netbsd:netbsd:2.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:netbsd:netbsd:3.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-03-23T11:06Z",
    "lastModifiedDate" : "2017-07-20T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0906",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "top_line",
            "product" : {
              "product_data" : [ {
                "product_name" : "d3jeeb_pro",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/19062",
          "name" : "19062",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1015687",
          "name" : "1015687",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/426197/100/0/threaded",
          "name" : "20060226 2 SQL Injection in d3jeeb",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16853",
          "name" : "16853",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0757",
          "name" : "ADV-2006-0757",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24941",
          "name" : "d3jeeb-catid-sql-injection(24941)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in D3Jeeb Pro 3 allows remote attackers to execute arbitrary SQL commands via the catid parameter in (1) fastlinks.php and (2) catogary.php."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:top_line:d3jeeb_pro:3:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-28T02:02Z",
    "lastModifiedDate" : "2018-10-18T16:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0907",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "francisco_burzi",
            "product" : {
              "product_data" : [ {
                "product_name" : "php-nuke",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.8",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/archive/1/426083/100/0/threaded",
          "name" : "20060225 [waraxe-2006-SA#047] - Evading sql-injection filters in phpNuke 7.8",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.waraxe.us/advisory-47.html",
          "name" : "http://www.waraxe.us/advisory-47.html",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in PHP-Nuke before 7.8 Patched 3.2 allows remote attackers to execute arbitrary SQL commands via encoded /%2a (/*) sequences in the query string, which bypasses regular expressions that are intended to protect against SQL injection, as demonstrated via the kala parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:francisco_burzi:php-nuke:7.8:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-28T02:02Z",
    "lastModifiedDate" : "2018-10-18T16:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0908",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "francisco_burzi",
            "product" : {
              "product_data" : [ {
                "product_name" : "php-nuke",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.8_patched_3.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://securityreason.com/securityalert/497",
          "name" : "497",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/426083/100/0/threaded",
          "name" : "20060225 [waraxe-2006-SA#047] - Evading sql-injection filters in phpNuke 7.8",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.waraxe.us/advisory-47.html",
          "name" : "http://www.waraxe.us/advisory-47.html",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "PHP-Nuke 7.8 Patched 3.2 allows remote attackers to bypass SQL injection protection mechanisms via /%2a (/*) sequences with the \"ad_click\" word in the query string, as demonstrated via the kala parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:francisco_burzi:php-nuke:7.8_patched_3.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-28T02:02Z",
    "lastModifiedDate" : "2018-10-18T16:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0909",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "invision_power_services",
            "product" : {
              "product_data" : [ {
                "product_name" : "invision_power_board",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.1.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.1_beta2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.1_beta3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.1_beta4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.1_beta5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.1_rc1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://neosecurityteam.net/advisories/Advisory-16.txt",
          "name" : "http://neosecurityteam.net/advisories/Advisory-16.txt",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://neosecurityteam.net/index.php?action=advisories&id=16",
          "name" : "http://neosecurityteam.net/index.php?action=advisories&id=16",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/425713/100/0/threaded",
          "name" : "20060221 Invision Power Board 2.1.4 Multiple Vulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/466275/100/0/threaded",
          "name" : "20070419 IPB (Invision Power Board) Full Path Disclusure",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24840",
          "name" : "invisionpowerboard-multiple-info-disclosure(24840)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Invision Power Board (IPB) 2.1.4 and earlier allows remote attackers to view sensitive information via a direct request to multiple PHP scripts that include the full path in error messages, including (1) PEAR/Text/Diff/Renderer/inline.php, (2) PEAR/Text/Diff/Renderer/unified.php, (3) PEAR/Text/Diff3.php, (4) class_db.php, (5) class_db_mysql.php, and (6) class_xml.php in the ips_kernel/ directory; (7) mysql_admin_queries.php, (8) mysql_extra_queries.php, (9) mysql_queries.php, and (10) mysql_subsm_queries.php in the sources/sql directory; (11) sources/acp_loaders/acp_pages_components.php; (12) sources/action_admin/member.php and (13) sources/action_admin/paysubscriptions.php; (14) login.php, (15) messenger.php, (16) moderate.php, (17) paysubscriptions.php, (18) register.php, (19) search.php, (20) topics.php, (21) and usercp.php in the sources/action_public directory; (22) bbcode/class_bbcode.php, (23) bbcode/class_bbcode_legacy.php, (24) editor/class_editor_rte.php, (25) editor/class_editor_std.php, (26) post/class_post.php, (27) post/class_post_edit.php, (28) post/class_post_new.php, (29) and post/class_post_reply.php in the sources/classes directory; (30) sources/components_acp/registration_DEPR.php; (31) sources/handlers/han_paysubscriptions.php; (32) func_usercp.php; (33) search_mysql_ftext.php, and (34) search_mysql_man.php in the sources/lib/ directory; and (35) convert/auth.php.bak, (36) external/auth.php, and (37) ldap/auth.php in the sources/loginauth directory."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:invision_power_services:invision_power_board:2.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:invision_power_services:invision_power_board:2.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:invision_power_services:invision_power_board:2.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:invision_power_services:invision_power_board:2.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:invision_power_services:invision_power_board:2.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:invision_power_services:invision_power_board:2.1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:invision_power_services:invision_power_board:2.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:invision_power_services:invision_power_board:2.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:invision_power_services:invision_power_board:2.1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:invision_power_services:invision_power_board:2.1.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:invision_power_services:invision_power_board:2.1_beta2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:invision_power_services:invision_power_board:2.1_beta3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:invision_power_services:invision_power_board:2.1_beta4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:invision_power_services:invision_power_board:2.1_beta5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:invision_power_services:invision_power_board:2.1_rc1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-28T11:02Z",
    "lastModifiedDate" : "2018-10-18T16:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0910",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "invision_power_services",
            "product" : {
              "product_data" : [ {
                "product_name" : "invision_power_board",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.1.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.1_beta2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.1_beta3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.1_beta4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.1_beta5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.1_rc1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://neosecurityteam.net/advisories/Advisory-16.txt",
          "name" : "http://neosecurityteam.net/advisories/Advisory-16.txt",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://neosecurityteam.net/index.php?action=advisories&id=16",
          "name" : "http://neosecurityteam.net/index.php?action=advisories&id=16",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/425713/100/0/threaded",
          "name" : "20060221 Invision Power Board 2.1.4 Multiple Vulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24840",
          "name" : "invisionpowerboard-multiple-info-disclosure(24840)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Invision Power Board (IPB) 2.1.4 and earlier allows remote attackers to list directory contents via a direct request to multiple directories, including (1) sources/loginauth/convert/, (2) sources/portal_plugins/, (3) cache/skin_cache/cacheid_2/, (4) ips_kernel/PEAR/, (5) ips_kernel/PEAR/Text/, (6) ips_kernel/PEAR/Text/Diff/, (7) ips_kernel/PEAR/Text/Diff/Renderer/, (8) style_images/1/folder_rte_files/, (9) style_images/1/folder_js_skin/, (10) style_images/1/folder_rte_images/, and (11) upgrade/ and its subdirectories."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:invision_power_services:invision_power_board:2.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:invision_power_services:invision_power_board:2.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:invision_power_services:invision_power_board:2.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:invision_power_services:invision_power_board:2.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:invision_power_services:invision_power_board:2.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:invision_power_services:invision_power_board:2.1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:invision_power_services:invision_power_board:2.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:invision_power_services:invision_power_board:2.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:invision_power_services:invision_power_board:2.1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:invision_power_services:invision_power_board:2.1.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:invision_power_services:invision_power_board:2.1_beta2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:invision_power_services:invision_power_board:2.1_beta3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:invision_power_services:invision_power_board:2.1_beta4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:invision_power_services:invision_power_board:2.1_beta5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:invision_power_services:invision_power_board:2.1_rc1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-28T11:02Z",
    "lastModifiedDate" : "2018-10-18T16:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0911",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ipswitch",
            "product" : {
              "product_data" : [ {
                "product_name" : "whatsup",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "professional_2006",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-399"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://securityreason.com/securityalert/472",
          "name" : "472",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/23494",
          "name" : "23494",
          "refsource" : "OSVDB",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/425780/100/0/threaded",
          "name" : "20060222 IpSwitch WhatsUp Professional 2006 DoS",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16771",
          "name" : "16771",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0704",
          "name" : "ADV-2006-0704",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://zur.homelinux.com/Advisories/ipswitch_dos.txt",
          "name" : "http://zur.homelinux.com/Advisories/ipswitch_dos.txt",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24864",
          "name" : "whatsup-nmservice-dos(24864)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "NmService.exe in Ipswitch WhatsUp Professional 2006 allows remote attackers to cause a denial of service (CPU consumption) via crafted requests to Login.asp, possibly involving the (1) \"In]\" and (2) \"b;tnLogIn\" parameters, or (3) malformed btnLogIn parameters, possibly involving missing \"[\" (open bracket) or \"[\" (closing bracket) characters, as demonstrated by \"&btnLogIn=[Log&In]=&\" or \"&b;tnLogIn=[Log&In]=&\" in the URL.  NOTE: due to the lack of diagnosis by the original researcher, the precise nature of the vulnerability is unclear."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ipswitch:whatsup:professional_2006:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-28T11:02Z",
    "lastModifiedDate" : "2018-10-18T16:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0912",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oreka",
            "product" : {
              "product_data" : [ {
                "product_name" : "oreka",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.4",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://oreka.sourceforge.net/",
          "name" : "http://oreka.sourceforge.net/",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/19095",
          "name" : "19095",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/23300",
          "name" : "23300",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16937",
          "name" : "16937",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0812",
          "name" : "ADV-2006-0812",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Oreka before 0.5 allows remote attackers to cause a denial of service (application crash) via a \"certain RTP sequence.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oreka:oreka:0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oreka:oreka:0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oreka:oreka:0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oreka:oreka:0.4:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-28T11:02Z",
    "lastModifiedDate" : "2011-03-08T02:31Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0913",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "mozilla",
            "product" : {
              "product_data" : [ {
                "product_name" : "bugzilla",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.17.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.17.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.17.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.17.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.17.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.17.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.18",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.18.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.18.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.18.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.18.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.19",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.19.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.19.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.19.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.20",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.21",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.21.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18979",
          "name" : "18979",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/23378",
          "name" : "23378",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/425584/100/0/threaded",
          "name" : "20060221 [BUGZILLA] Security Advisory for Bugzilla 2.20, 2.21.1, and 2.18.4",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16738",
          "name" : "16738",
          "refsource" : "BID",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0692",
          "name" : "ADV-2006-0692",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://bugzilla.mozilla.org/show_bug.cgi?id=312498",
          "name" : "https://bugzilla.mozilla.org/show_bug.cgi?id=312498",
          "refsource" : "CONFIRM",
          "tags" : [ "Exploit", "Patch", "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24819",
          "name" : "bugzilla-editparams-sql-injection(24819)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in whineatnews.pl in Bugzilla 2.17 through 2.18.4 and 2.20 allows remote authenticated users with administrative privileges to execute arbitrary SQL commands via the whinedays parameter, as accessible from editparams.cgi."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:bugzilla:2.17.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:bugzilla:2.17.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:bugzilla:2.17.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:bugzilla:2.17.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:bugzilla:2.17.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:bugzilla:2.17.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:bugzilla:2.18:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:bugzilla:2.18:rc2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:bugzilla:2.18:rc3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:bugzilla:2.18.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:bugzilla:2.18.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:bugzilla:2.18.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:bugzilla:2.18.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:bugzilla:2.19:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:bugzilla:2.19.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:bugzilla:2.19.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:bugzilla:2.19.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:bugzilla:2.20:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:bugzilla:2.20:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:bugzilla:2.20:rc2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:bugzilla:2.21:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:bugzilla:2.21.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:N/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.5
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.0,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-28T11:02Z",
    "lastModifiedDate" : "2018-10-18T16:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0914",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "mozilla",
            "product" : {
              "product_data" : [ {
                "product_name" : "bugzilla",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.16.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.17",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.17.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.17.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.17.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.17.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.18",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.18.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.18.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.18.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.18.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.20",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-20"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/archive/1/425584/100/0/threaded",
          "name" : "20060221 [BUGZILLA] Security Advisory for Bugzilla 2.20, 2.21.1, and 2.18.4",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0692",
          "name" : "ADV-2006-0692",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://bugzilla.mozilla.org/show_bug.cgi?id=312498",
          "name" : "https://bugzilla.mozilla.org/show_bug.cgi?id=312498",
          "refsource" : "CONFIRM",
          "tags" : [ "Exploit", "Patch", "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/42802",
          "name" : "bugzilla-duplicates-sql-injection(42802)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Bugzilla 2.16.10, 2.17 through 2.18.4, and 2.20 does not properly handle certain characters in the mostfreqthreshold parameter in duplicates.cgi, which allows remote attackers to trigger a SQL error."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:bugzilla:2.16.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:bugzilla:2.17:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:bugzilla:2.17.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:bugzilla:2.17.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:bugzilla:2.17.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:bugzilla:2.17.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:bugzilla:2.18:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:bugzilla:2.18:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:bugzilla:2.18:rc2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:bugzilla:2.18.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:bugzilla:2.18.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:bugzilla:2.18.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:bugzilla:2.18.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:bugzilla:2.20:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:bugzilla:2.20:rc2:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:N/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.5
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.0,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-28T11:02Z",
    "lastModifiedDate" : "2018-10-18T16:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0915",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "mozilla",
            "product" : {
              "product_data" : [ {
                "product_name" : "bugzilla",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.16.10",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.vupen.com/english/advisories/2006/0692",
          "name" : "ADV-2006-0692",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://bugzilla.mozilla.org/show_bug.cgi?id=313441",
          "name" : "https://bugzilla.mozilla.org/show_bug.cgi?id=313441",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Bugzilla 2.16.10 does not properly handle certain characters in the (1) maxpatchsize and (2) maxattachmentsize parameters in attachment.cgi, which allows remote attackers to trigger a SQL error."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:bugzilla:2.16.10:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-28T11:02Z",
    "lastModifiedDate" : "2011-03-08T02:31Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0916",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "mozilla",
            "product" : {
              "product_data" : [ {
                "product_name" : "bugzilla",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.19.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.20",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.21",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.21.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.21.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18979",
          "name" : "18979",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/464",
          "name" : "464",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/425584/100/0/threaded",
          "name" : "20060221 [BUGZILLA] Security Advisory for Bugzilla 2.20, 2.21.1, and 2.18.4",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16745",
          "name" : "16745",
          "refsource" : "BID",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0692",
          "name" : "ADV-2006-0692",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://bugzilla.mozilla.org/show_bug.cgi?id=325079",
          "name" : "https://bugzilla.mozilla.org/show_bug.cgi?id=325079",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24821",
          "name" : "bugzilla-login-data-redirection(24821)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Bugzilla 2.19.3 through 2.20 does not properly handle \"//\" sequences in URLs when redirecting a user from the login form, which could cause it to generate a partial URL in a form action that causes the user's browser to send the form data to another domain."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:bugzilla:2.19.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:bugzilla:2.20:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:bugzilla:2.20:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:bugzilla:2.20:rc2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:bugzilla:2.21:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:bugzilla:2.21.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:bugzilla:2.21.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-28T11:02Z",
    "lastModifiedDate" : "2018-10-18T16:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0917",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "melange",
            "product" : {
              "product_data" : [ {
                "product_name" : "melange_chat_system",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.10",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18984",
          "name" : "18984",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/463",
          "name" : "463",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.oh2600.com/forum/viewtopic.php?t=43",
          "name" : "http://www.oh2600.com/forum/viewtopic.php?t=43",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/425589/100/0/threaded",
          "name" : "20060221 grab cookie information with Melange Chat Server 1.10",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16747",
          "name" : "16747",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24868",
          "name" : "melange-chat-command-information-disclosure(24868)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Melange Chat Server (aka M-Chat), when accessed via a web browser, automatically sends cookies and other sensitive information for a server to any port specified in the associated link, which allows local users on that server to read the cookies from HTTP headers and possibly gain sensitive information, such as credentials, by setting up a listening port and reading the credentials when the victim clicks on the link."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:melange:melange_chat_system:1.10:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 2.1
        },
        "severity" : "LOW",
        "exploitabilityScore" : 3.9,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-28T11:02Z",
    "lastModifiedDate" : "2018-10-18T16:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0918",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ritlabs",
            "product" : {
              "product_data" : [ {
                "product_name" : "the_bat",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.60.07",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18989",
          "name" : "18989",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/485",
          "name" : "485",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.nsag.ru/vuln/953.html",
          "name" : "http://www.nsag.ru/vuln/953.html",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/425936/100/0/threaded",
          "name" : "20060223 NSA Group Security Advisory NSAG-&sup1;198-23.02.2006 Vulnerability The Bat v. 3.60.07",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16797",
          "name" : "16797",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0717",
          "name" : "ADV-2006-0717",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24882",
          "name" : "thebat-subject-bo(24882)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Buffer overflow in RITLabs The Bat! 3.60.07 allows remote attackers to execute arbitrary code via a long Subject field."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ritlabs:the_bat:3.60.07:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-28T11:02Z",
    "lastModifiedDate" : "2018-10-18T16:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0919",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oi",
            "product" : {
              "product_data" : [ {
                "product_name" : "email_marketing_system",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18993",
          "name" : "18993",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://www.h4cky0u.org/advisories/HYSA-2006-003-oi-email.txt",
          "name" : "http://www.h4cky0u.org/advisories/HYSA-2006-003-oi-email.txt",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/23462",
          "name" : "23462",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/425924/100/0/threaded",
          "name" : "20060223 HYSA-2006-003 Oi! Email Marketing 3.0 SQL Injection",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0718",
          "name" : "ADV-2006-0718",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in index.php (aka the login page) in Oi! Email Marketing System 3.0 (aka Oi! 3) allows remote attackers to execute arbitrary SQL commands via the (1) Username and (2) Password fields."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oi:email_marketing_system:3.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-28T11:02Z",
    "lastModifiedDate" : "2018-10-18T16:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0920",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oi",
            "product" : {
              "product_data" : [ {
                "product_name" : "email_marketing_system",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://securityreason.com/securityalert/483",
          "name" : "483",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.h4cky0u.org/advisories/HYSA-2006-003-oi-email.txt",
          "name" : "http://www.h4cky0u.org/advisories/HYSA-2006-003-oi-email.txt",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/425924/100/0/threaded",
          "name" : "20060223 HYSA-2006-003 Oi! Email Marketing 3.0 SQL Injection",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16794",
          "name" : "16794",
          "refsource" : "BID",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Oi! Email Marketing System 3.0 (aka Oi! 3) stores the server's FTP password in cleartext on a Configuration web page, which allows local users with superadministrator privileges, or attackers who have obtained access to the web page, to view the password."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oi:email_marketing_system:3.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:S/C:P/I:N/A:N",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 1.7
        },
        "severity" : "LOW",
        "exploitabilityScore" : 3.1,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-28T11:02Z",
    "lastModifiedDate" : "2018-10-18T16:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0921",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "fckeditor",
            "product" : {
              "product_data" : [ {
                "product_name" : "fckeditor",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0_fc",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://securityreason.com/securityalert/484",
          "name" : "484",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.nsag.ru/vuln/952.html",
          "name" : "http://www.nsag.ru/vuln/952.html",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/425937/100/0/threaded",
          "name" : "20060223 NSA Group Security Advisory NSAG-&sup1;195-23.02.2006 Vulnerability FCKeditor 2.0 FC",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/434559/30/4890/threaded",
          "name" : "20060519 Re: NSA Group Security Advisory NSAG-&sup1;195-23.02.2006 Vulnerability FCKeditor 2.0 FC",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24878",
          "name" : "fckeditor-connector-obtain-information(24878)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple directory traversal vulnerabilities in connector.php in FCKeditor 2.0 FC, as used in products such as RunCMS, allow remote attackers to list and create arbitrary directories via a .. (dot dot) in the CurrentFolder parameter to (1) GetFoldersAndFiles and (2) CreateFolder."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:fckeditor:fckeditor:2.0_fc:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 6.4
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-28T11:02Z",
    "lastModifiedDate" : "2018-10-18T16:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0922",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "devellion",
            "product" : {
              "product_data" : [ {
                "product_name" : "cubecart",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.0.0_alpha",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.0_alpha-2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.0_alpha-rgf",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.0_beta",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.0_final",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.6",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://securityreason.com/securityalert/482",
          "name" : "482",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.cubecart.com/site/forums/index.php?showtopic=14704",
          "name" : "http://www.cubecart.com/site/forums/index.php?showtopic=14704",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.cubecart.com/site/forums/index.php?showtopic=14817",
          "name" : "http://www.cubecart.com/site/forums/index.php?showtopic=14817",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.cubecart.com/site/forums/index.php?showtopic=14825",
          "name" : "http://www.cubecart.com/site/forums/index.php?showtopic=14825",
          "refsource" : "MISC",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.cubecart.com/site/forums/index.php?showtopic=14960",
          "name" : "http://www.cubecart.com/site/forums/index.php?showtopic=14960",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.cubecart.com/site/forums/index.php?showtopic=14972",
          "name" : "http://www.cubecart.com/site/forums/index.php?showtopic=14972",
          "refsource" : "MISC",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.nsag.ru/vuln/892.html",
          "name" : "http://www.nsag.ru/vuln/892.html",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/425931/100/0/threaded",
          "name" : "20060223 NSA Group Security Advisory NSAG-&sup1;197-23.02.2006 Vulnerability CubeCart 3.0.0 ? 3.0.6",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16796",
          "name" : "16796",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24883",
          "name" : "cubecart-connector-file-include(24883)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "CubeCart 3.0 through 3.6 does not properly check authorization for an administration session because of a missing auth.inc.php include, which results in an absolute path traversal vulnerability in FileUpload in connector.php (aka upload.php) that allows remote attackers to upload arbitrary files via a modified CurrentFolder parameter in a direct request to admin/filemanager/upload.php."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:devellion:cubecart:3.0.0_alpha:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:devellion:cubecart:3.0.0_alpha-2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:devellion:cubecart:3.0.0_alpha-rgf:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:devellion:cubecart:3.0.0_beta:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:devellion:cubecart:3.0.0_final:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:devellion:cubecart:3.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:devellion:cubecart:3.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:devellion:cubecart:3.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:devellion:cubecart:3.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:devellion:cubecart:3.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:devellion:cubecart:3.0.6:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-28T11:02Z",
    "lastModifiedDate" : "2018-10-18T16:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0923",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "myphpnuke",
            "product" : {
              "product_data" : [ {
                "product_name" : "myphpnuke",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.8.8",
                    "version_affected" : "<="
                  }, {
                    "version_value" : "1.8.8_7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.8.8_8_rc2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/19052",
          "name" : "19052",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/491",
          "name" : "491",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.myphpnuke.com/article.php?sid=1035&mode=thread&order=0",
          "name" : "http://www.myphpnuke.com/article.php?sid=1035&mode=thread&order=0",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.nukedx.com/?viewdoc=12",
          "name" : "http://www.nukedx.com/?viewdoc=12",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/425983/100/0/threaded",
          "name" : "20060224 Advisory: MyPHPNuke <= 1.8.8 multiple XSS vulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16815",
          "name" : "16815",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0750",
          "name" : "ADV-2006-0750",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24887",
          "name" : "myphpnuke-reviews-download-xss(24887)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple cross-site scripting (XSS) vulnerabilities in MyPHPNuke (MPN) 1.88 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the letter parameter in reviews.php and (2) the dcategory parameter in download.php."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:myphpnuke:myphpnuke:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.8.8"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:myphpnuke:myphpnuke:1.8.8_7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:myphpnuke:myphpnuke:1.8.8_8_rc2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-28T11:02Z",
    "lastModifiedDate" : "2018-10-18T16:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0924",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "brown_bear_software",
            "product" : {
              "product_data" : [ {
                "product_name" : "ical",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.10",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/19001",
          "name" : "19001",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/23472",
          "name" : "23472",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16845",
          "name" : "16845",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0727",
          "name" : "ADV-2006-0727",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24919",
          "name" : "ical-calendartext-xss(24919)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in Brown Bear iCal 3.10 allows remote attackers to inject arbitrary web script or HTML via the Calendar Text field when a new event is added.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information."
        }, {
          "lang" : "en",
          "value" : "This vulnerability affects Brown Bear iCal version 3.10 and previous."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:brown_bear_software:ical:3.10:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-28T11:02Z",
    "lastModifiedDate" : "2017-07-20T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0925",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "alt-n",
            "product" : {
              "product_data" : [ {
                "product_name" : "mdaemon",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.1.4",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18921",
          "name" : "18921",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.nsag.ru/vuln/888.html",
          "name" : "http://www.nsag.ru/vuln/888.html",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16854",
          "name" : "16854",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0729",
          "name" : "ADV-2006-0729",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24916",
          "name" : "mdaemon-imap-foldername-dos(24916)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Format string vulnerability in the IMAP4rev1 server in Alt-N MDaemon 8.1.1 and possibly 8.1.4 allows remote attackers to cause a denial of service (CPU consumption) by creating and then listing folders whose names contain format string specifiers."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:alt-n:mdaemon:8.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:alt-n:mdaemon:8.1.4:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-28T11:02Z",
    "lastModifiedDate" : "2017-07-20T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0926",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "smithmicro",
            "product" : {
              "product_data" : [ {
                "product_name" : "stuffit_deluxe",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "stuffit_expander",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9.0.0.21_engine_9.0.0.21",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "stuffit_standard",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "zipmagic_deluxe",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/19010",
          "name" : "19010",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.hamid.ir/security/stuffit.txt",
          "name" : "http://www.hamid.ir/security/stuffit.txt",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/23463",
          "name" : "23463",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/425972/100/0/threaded",
          "name" : "20060224 StuffIt and ZipMagic Family of products Directory traversal",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16806",
          "name" : "16806",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0732",
          "name" : "ADV-2006-0732",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24886",
          "name" : "stuffit-zipmagic-archive-directory-traversal(24886)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple directory traversal vulnerabilities in Allume StuffIt Standard and Deluxe 9.0, ZipMagic Deluxe 9.0, and StuffIt Expander 9.0.0.21 Engine 9.0.0.21 allow remote attackers to create and overwrite arbitrary files via certain crafted pathnames in a (1) zip or (2) tar archive."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:smithmicro:stuffit_deluxe:9.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:smithmicro:stuffit_expander:9.0.0.21_engine_9.0.0.21:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:smithmicro:stuffit_standard:9.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:smithmicro:zipmagic_deluxe:9.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:H/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "HIGH",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 2.6
        },
        "severity" : "LOW",
        "exploitabilityScore" : 4.9,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2006-02-28T11:02Z",
    "lastModifiedDate" : "2018-10-18T16:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0927",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "jgs-xa",
            "product" : {
              "product_data" : [ {
                "product_name" : "jgs-gallery_addon",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "woltlab",
            "product" : {
              "product_data" : [ {
                "product_name" : "burning_board",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.1.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.3.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.3.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://archives.neohapsis.com/archives/fulldisclosure/2006-02/0615.html",
          "name" : "20060224 Advisory: Woltlab Burning Board 2.x (JGS-Gallery MOD <= 4.0) multiple XSS vulnerabilities",
          "refsource" : "FULLDISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.nukedx.com/?viewdoc=11",
          "name" : "http://www.nukedx.com/?viewdoc=11",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/425981/100/0/threaded",
          "name" : "20060224 Advisory: Woltlab Burning Board 2.x (JGS-Gallery MOD <= 4.0)multiple XSS vulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16810",
          "name" : "16810",
          "refsource" : "BID",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16843",
          "name" : "16843",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24888",
          "name" : "wbb-jgsgallerymod-xss(24888)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple cross-site scripting (XSS) vulnerabilities in the JGS-XA JGS-Gallery Addon 4.0.0 and earlier for Woltlab Burning Board (wBB) 2.x allow remote attackers to inject arbitrary web script or HTML via the (1) userid parameter in (a) jgs_galerie_slideshow.php and (b) jgs_galerie_scroll.php, and the (2) katid parameter in (c) jgs_galerie_slideshow.php."
        }, {
          "lang" : "en",
          "value" : "Vulnerability affects JGS-XA, JGS-Gallery Addon versions 4.0.0 and previous."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:jgs-xa:jgs-gallery_addon:4.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:woltlab:burning_board:2.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:woltlab:burning_board:2.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:woltlab:burning_board:2.1.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:woltlab:burning_board:2.2.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:woltlab:burning_board:2.2.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:woltlab:burning_board:2.2.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:woltlab:burning_board:2.3.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:woltlab:burning_board:2.3.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:H/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "HIGH",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 2.6
        },
        "severity" : "LOW",
        "exploitabilityScore" : 4.9,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2006-02-28T11:02Z",
    "lastModifiedDate" : "2018-10-18T16:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0928",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "argosoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "argosoft_mail_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.8",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18990",
          "name" : "18990",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.nsag.ru/vuln/879.html",
          "name" : "http://www.nsag.ru/vuln/879.html",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/425968/100/0/threaded",
          "name" : "20060224 NSA Group Security Advisory NSAG-&sup1;198-23.02.2006 Vulnerability ArGoSoft Mail Server Pro",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16808",
          "name" : "16808",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0733",
          "name" : "ADV-2006-0733",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The POP3 Server in ArGoSoft Mail Server Pro 1.8 allows remote attackers to obtain sensitive information via the _DUMP command, which reveals the operating system, registered user, and registration code."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:argosoft:argosoft_mail_server:1.8:*:pro:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-28T11:02Z",
    "lastModifiedDate" : "2018-10-18T16:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0929",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "argosoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "argosoft_mail_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.8.8.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18990",
          "name" : "18990",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.nsag.ru/vuln/878.html",
          "name" : "http://www.nsag.ru/vuln/878.html",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/425969/100/0/threaded",
          "name" : "20060224 NSA Group Security Advisory NSAG-&sup1;200-24.02.2006 Vulnerability ArGoSoft Mail Server Pro IMAP",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16809",
          "name" : "16809",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0733",
          "name" : "ADV-2006-0733",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Directory traversal vulnerability in the IMAP server in ArGoSoft Mail Server Pro 1.8.8.1 allows remote authenticated users to create arbitrary folders via a .. (dot dot) in the RENAME command."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:argosoft:argosoft_mail_server:1.8.8.1:*:pro:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-28T11:02Z",
    "lastModifiedDate" : "2018-10-18T16:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0930",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "argosoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "argosoft_mail_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.8",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18990",
          "name" : "18990",
          "refsource" : "SECUNIA",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/487",
          "name" : "487",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.nsag.ru/vuln/877.html",
          "name" : "http://www.nsag.ru/vuln/877.html",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0733",
          "name" : "ADV-2006-0733",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Directory traversal vulnerability in Webmail in ArGoSoft Mail Server Pro 1.8 allows remote authenticated users to read arbitrary files via a .. (dot dot) in the UIDL parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:argosoft:argosoft_mail_server:1.8:*:pro:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-28T11:02Z",
    "lastModifiedDate" : "2011-03-08T02:31Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0931",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "pear",
            "product" : {
              "product_data" : [ {
                "product_name" : "pear_archive_tar",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.2",
                    "version_affected" : "<="
                  }, {
                    "version_value" : "1.3.0",
                    "version_affected" : "<="
                  }, {
                    "version_value" : "1.3.1",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-22"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://pear.php.net/bugs/bug.php?id=6933",
          "name" : "http://pear.php.net/bugs/bug.php?id=6933",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://pear.php.net/package/Archive_Tar/download/",
          "name" : "http://pear.php.net/package/Archive_Tar/download/",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/19011",
          "name" : "19011",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.hamid.ir/security/phptar.txt",
          "name" : "http://www.hamid.ir/security/phptar.txt",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/23481",
          "name" : "23481",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/425967/100/0/threaded",
          "name" : "20060224 Archive_Tar v 1.2(Tested) (Tar file management class) Directory traversal",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16805",
          "name" : "16805",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0728",
          "name" : "ADV-2006-0728",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Directory traversal vulnerability in PEAR::Archive_Tar 1.2, and other versions before 1.3.2, allows remote attackers to create and overwrite arbitrary files via certain crafted pathnames in a TAR archive."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pear:pear_archive_tar:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.2"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pear:pear_archive_tar:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.3.0"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pear:pear_archive_tar:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.3.1"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-28T11:02Z",
    "lastModifiedDate" : "2018-10-18T16:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0932",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "pear",
            "product" : {
              "product_data" : [ {
                "product_name" : "pear_archive_zip",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://securityreason.com/securityalert/486",
          "name" : "486",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.hamid.ir/security/phpzip.txt",
          "name" : "http://www.hamid.ir/security/phpzip.txt",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/425967/100/0/threaded",
          "name" : "20060224 Archive_Tar v 1.2(Tested) (Tar file management class) Directory traversal",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/426153/100/0/threaded",
          "name" : "20060225 Archive_Zip (Zip file management class) Directory traversal",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24972",
          "name" : "ziplib-directory-traversal(24972)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Directory traversal vulnerability in zip.lib.php 0.1.1 in PEAR::Archive_Zip allows remote attackers to create and overwrite arbitrary files via certain crafted pathnames in a ZIP archive."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pear:pear_archive_zip:1.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-28T11:02Z",
    "lastModifiedDate" : "2018-10-18T16:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0933",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "phpx",
            "product" : {
              "product_data" : [ {
                "product_name" : "phpx",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.5.9",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18688",
          "name" : "18688",
          "refsource" : "SECUNIA",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16799",
          "name" : "16799",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0722",
          "name" : "ADV-2006-0722",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24874",
          "name" : "phpx-xcode-tag-xss(24874)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in PHPX 3.5.9 allows remote attackers to inject arbitrary web script or HTML via a javascript URI in a url XCode tag in a posted message.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:phpx:phpx:3.5.9:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-28T11:02Z",
    "lastModifiedDate" : "2017-07-20T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0934",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "limbo_cms",
            "product" : {
              "product_data" : [ {
                "product_name" : "limbo_cms",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0.4.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://osvdb.org/ref/23/23469-limbo.txt",
          "name" : "http://osvdb.org/ref/23/23469-limbo.txt",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18723",
          "name" : "18723",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/23469",
          "name" : "23469",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16811",
          "name" : "16811",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0721",
          "name" : "ADV-2006-0721",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24877",
          "name" : "webinsta-limbo-contact-form-xss(24877)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in webinsta Limbo 1.0.4.2 allows remote attackers to inject arbitrary web script or HTML via the message field in the Contact Form."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:limbo_cms:limbo_cms:1.0.4.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-28T11:02Z",
    "lastModifiedDate" : "2017-07-20T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0935",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "word",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2003",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://archives.neohapsis.com/archives/dailydave/2006-q1/0179.html",
          "name" : "[Dailydave] 20060221 word dos 4fun",
          "refsource" : "MLIST",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16782",
          "name" : "16782",
          "refsource" : "BID",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Microsoft Word 2003 allows remote attackers to cause a denial of service (application crash) via a crafted file, as demonstrated by 101_filefuzz."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:word:2003:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:H/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "HIGH",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 2.6
        },
        "severity" : "LOW",
        "exploitabilityScore" : 4.9,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2006-02-28T11:02Z",
    "lastModifiedDate" : "2008-09-05T21:00Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0936",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "free_host_shop",
            "product" : {
              "product_data" : [ {
                "product_name" : "website_generator",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://nsag.ru/vuln/894.html",
          "name" : "http://nsag.ru/vuln/894.html",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/19014",
          "name" : "19014",
          "refsource" : "SECUNIA",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/426077/100/0/threaded",
          "name" : "20060225 NSA Group Security Advisory NSAG-&sup1;202-25.02.2006 Vulnerability WEBSITE GENERATOR 3.3",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16823",
          "name" : "16823",
          "refsource" : "BID",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Free Host Shop Website Generator 3.3 allows remote authenticated users with administrative privileges to upload and execute arbitrary files via a formname parameter with a filename containing a dangerous file extension and a trailing %00."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:free_host_shop:website_generator:3.3:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.5
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : true,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-28T11:02Z",
    "lastModifiedDate" : "2018-10-18T16:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0937",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "unu_networks",
            "product" : {
              "product_data" : [ {
                "product_name" : "mailgust",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.9",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://nsag.ru/vuln/890.html",
          "name" : "http://nsag.ru/vuln/890.html",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/18998",
          "name" : "18998",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24890",
          "name" : "mailgust-index-info-disclosure(24890)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "U.N.U. Mailgust 1.9 allows remote attackers to obtain sensitive information via a direct request to index.php with method=showfullcsv, which reveals the POP3 server configuration, including account name and password."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:unu_networks:mailgust:1.9:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-02-28T11:02Z",
    "lastModifiedDate" : "2017-07-20T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0938",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ez",
            "product" : {
              "product_data" : [ {
                "product_name" : "ez_publish",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.4.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.5.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.5.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.5.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.5.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.5.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.6.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.6.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.6.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.6.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.6.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.7.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.7.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.7.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.7.3",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://securitytracker.com/id?1015683",
          "name" : "1015683",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.nukedx.com/?viewdoc=16",
          "name" : "http://www.nukedx.com/?viewdoc=16",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/426076/100/0/threaded",
          "name" : "20060225 Advisory: eZ publish <= 3.7.3 (imagecatalogue module) XSSvulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16817",
          "name" : "16817",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24956",
          "name" : "ezpublish-referrerurl-xss(24956)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in eZ publish 3.7.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the RefererURL parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ez:ez_publish:3.4.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ez:ez_publish:3.5.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ez:ez_publish:3.5.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ez:ez_publish:3.5.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ez:ez_publish:3.5.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ez:ez_publish:3.5.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ez:ez_publish:3.6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ez:ez_publish:3.6.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ez:ez_publish:3.6.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ez:ez_publish:3.6.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ez:ez_publish:3.6.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ez:ez_publish:3.6.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ez:ez_publish:3.7.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ez:ez_publish:3.7.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ez:ez_publish:3.7.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ez:ez_publish:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "3.7.3"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-03-01T02:02Z",
    "lastModifiedDate" : "2018-10-18T16:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0939",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "dci-designs",
            "product" : {
              "product_data" : [ {
                "product_name" : "dci-taskeen",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.03",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://securityreason.com/securityalert/495",
          "name" : "495",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1015685",
          "name" : "1015685",
          "refsource" : "SECTRACK",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/426082",
          "name" : "20060225 SQL Injection in DCI-Taskeen",
          "refsource" : "BUGTRAQ",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16828",
          "name" : "16828",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24963",
          "name" : "dci-taskeen-multiple-scripts-sql-injection(24963)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in DCI-Taskeen 1.03 allows remote attackers to execute arbitrary SQL commands via the (1) id or (2) action parameter to (a) basket.php, or (3) id or (4) page parameter to (b) cat.php."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:dci-designs:dci-taskeen:1.03:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-03-01T02:02Z",
    "lastModifiedDate" : "2017-07-20T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0940",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "cynical_games",
            "product" : {
              "product_data" : [ {
                "product_name" : "shoutlive",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.1.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://evuln.com/vulns/87/summary.html",
          "name" : "http://evuln.com/vulns/87/summary.html",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/19047",
          "name" : "19047",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/557",
          "name" : "557",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/23482",
          "name" : "23482",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/426985/100/0/threaded",
          "name" : "20060307 [eVuln] ShoutLIVE PHP Code Execution & Multiple XSS Vulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16857",
          "name" : "16857",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0755",
          "name" : "ADV-2006-0755",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24897",
          "name" : "shoutlive-savesettings-file-include(24897)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple direct static code injection vulnerabilities in savesettings.php in ShoutLIVE 1.1.0 allow remote attackers to execute arbitrary PHP code via variables that are written to settings.php."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cynical_games:shoutlive:1.1.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-03-01T02:02Z",
    "lastModifiedDate" : "2018-10-18T16:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0941",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "cynical_games",
            "product" : {
              "product_data" : [ {
                "product_name" : "shoutlive",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.1.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://evuln.com/vulns/87/summary.html",
          "name" : "http://evuln.com/vulns/87/summary.html",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/19047",
          "name" : "19047",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/557",
          "name" : "557",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/23483",
          "name" : "23483",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/426985/100/0/threaded",
          "name" : "20060307 [eVuln] ShoutLIVE PHP Code Execution & Multiple XSS Vulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16857",
          "name" : "16857",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0755",
          "name" : "ADV-2006-0755",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24901",
          "name" : "shoutlive-post-xss(24901)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple cross-site scripting (XSS) vulnerabilities in post.php in ShoutLIVE 1.1.0 allow remote attackers to inject arbitrary web script or HTML via certain variables when posting new messages."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cynical_games:shoutlive:1.1.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-03-01T02:02Z",
    "lastModifiedDate" : "2018-10-18T16:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0942",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "pwsphp",
            "product" : {
              "product_data" : [ {
                "product_name" : "pwsphp",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.2.3",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://downloads.securityfocus.com/vulnerabilities/exploits/PwsPHP_SQL_Inj.php",
          "name" : "http://downloads.securityfocus.com/vulnerabilities/exploits/PwsPHP_SQL_Inj.php",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.osvdb.org/28444",
          "name" : "28444",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16567",
          "name" : "16567",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in profil.php in PwsPHP 1.2.3, and possibly earlier versions, allows remote attackers to execute arbitrary SQL commands via the aff_news_form parameter, a different vulnerability than CVE-2005-1509."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pwsphp:pwsphp:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.2.3"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-03-01T02:02Z",
    "lastModifiedDate" : "2008-09-05T21:00Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0943",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "pwsphp",
            "product" : {
              "product_data" : [ {
                "product_name" : "pwsphp",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.2.3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://securityreason.com/securityalert/496",
          "name" : "496",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1015684",
          "name" : "1015684",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.pwsphp.com/index.php?mod=news&ac=commentaires&id=278",
          "name" : "http://www.pwsphp.com/index.php?mod=news&ac=commentaires&id=278",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/426084/100/0/threaded",
          "name" : "20060225 PwsPHP Injection SQL on Index.php",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/426183/100/0/threaded",
          "name" : "20060226 Re: PwsPHP Injection SQL on Index.php",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0748",
          "name" : "ADV-2006-0748",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in the sondages module in index.php in PwsPHP 1.2.3 allows remote attackers to execute arbitrary SQL commands via the id parameter to index.php."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pwsphp:pwsphp:1.2.3:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-03-01T02:02Z",
    "lastModifiedDate" : "2018-10-18T16:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0944",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "archangelmgt",
            "product" : {
              "product_data" : [ {
                "product_name" : "weblog",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.90.02",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://securitytracker.com/id?1015689",
          "name" : "1015689",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/23620",
          "name" : "23620",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/426184/100/0/threaded",
          "name" : "20060226 Archangel Weblog 0.90.02 Admin Authentication Bypass & Remote File Inclusion",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16848",
          "name" : "16848",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24984",
          "name" : "archangel-admin-auth-bypass(24984)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/3859",
          "name" : "3859",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Archangel Weblog 0.90.02 allows remote attackers to bypass authentication by setting the ba_admin cookie to 1."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:archangelmgt:weblog:0.90.02:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-03-01T02:02Z",
    "lastModifiedDate" : "2018-10-18T16:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0945",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "archangelmgt",
            "product" : {
              "product_data" : [ {
                "product_name" : "weblog",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.90.02",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-94"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://securitytracker.com/id?1015689",
          "name" : "1015689",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/23621",
          "name" : "23621",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/426184/100/0/threaded",
          "name" : "20060226 Archangel Weblog 0.90.02 Admin Authentication Bypass & Remote File Inclusion",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16848",
          "name" : "16848",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/25142",
          "name" : "archangel-index-file-include(25142)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "PHP remote file include vulnerability in admin/index.php in Archangel Weblog 0.90.02 allows remote authenticated administrators to execute arbitrary PHP code via a URL ending in a NULL (%00) in the index parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:archangelmgt:weblog:0.90.02:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.5
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-03-01T02:02Z",
    "lastModifiedDate" : "2018-10-18T16:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0946",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "thomson",
            "product" : {
              "product_data" : [ {
                "product_name" : "speedtouch",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "516_5.3.2.6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "530_5.3.2.6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "536_5.3.2.6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "546_5.3.2.6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "576_5.3.2.6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "580_5.3.2.6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "585_5.3.2.6.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/19069",
          "name" : "19069",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1015688",
          "name" : "1015688",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/23527",
          "name" : "23527",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/426186",
          "name" : "20060226 Thomson SpeedTouch 500 modems vulnerable to XSS",
          "refsource" : "BUGTRAQ",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16839",
          "name" : "16839",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0765",
          "name" : "ADV-2006-0765",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24977",
          "name" : "speedtouch-localnetwork-xss(24977)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in Thomson SpeedTouch modems running firmware 5.3.2.6.0 allows remote attackers to inject arbitrary web script or HTML via the name parameter to the LocalNetwork page."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:thomson:speedtouch:516_5.3.2.6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:thomson:speedtouch:530_5.3.2.6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:thomson:speedtouch:536_5.3.2.6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:thomson:speedtouch:546_5.3.2.6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:thomson:speedtouch:576_5.3.2.6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:thomson:speedtouch:580_5.3.2.6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:thomson:speedtouch:585_5.3.2.6.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-03-01T02:02Z",
    "lastModifiedDate" : "2017-07-20T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0947",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "thomson",
            "product" : {
              "product_data" : [ {
                "product_name" : "speedtouch",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "516_5.3.2.6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "530_5.3.2.6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "536_5.3.2.6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "546_5.3.2.6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "576_5.3.2.6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "580_5.3.2.6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "585_5.3.2.6.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/19069",
          "name" : "19069",
          "refsource" : "SECUNIA",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1015688",
          "name" : "1015688",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/426186",
          "name" : "20060226 Thomson SpeedTouch 500 modems vulnerable to XSS",
          "refsource" : "BUGTRAQ",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16839",
          "name" : "16839",
          "refsource" : "BID",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0765",
          "name" : "ADV-2006-0765",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Thomson SpeedTouch modem running firmware 5.3.2.6.0 allows remote attackers to create users that cannot be deleted via scripting code in the \"31\" parameter in a NewUser function, which is not filtered by the modem when creating the account, but cannot be deleted by the administrator, possibly due to cleansing that occurs in the administrator interface."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:thomson:speedtouch:516_5.3.2.6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:thomson:speedtouch:530_5.3.2.6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:thomson:speedtouch:536_5.3.2.6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:thomson:speedtouch:546_5.3.2.6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:thomson:speedtouch:576_5.3.2.6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:thomson:speedtouch:580_5.3.2.6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:thomson:speedtouch:585_5.3.2.6.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-03-01T02:02Z",
    "lastModifiedDate" : "2011-03-08T02:31Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0948",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "aol",
            "product" : {
              "product_data" : [ {
                "product_name" : "aol",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9.0_4184.2340",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/18734",
          "name" : "18734",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/secunia_research/2006-08",
          "name" : "http://secunia.com/secunia_research/2006-08",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/1416",
          "name" : "1416",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1016717",
          "name" : "1016717",
          "refsource" : "SECTRACK",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.osvdb.org/27995",
          "name" : "27995",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/443622/100/0/threaded",
          "name" : "20060818 Secunia Research: AOL Insecure Default Directory Permissions",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/19583",
          "name" : "19583",
          "refsource" : "BID",
          "tags" : [ "Patch" ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/3317",
          "name" : "ADV-2006-3317",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/28445",
          "name" : "aol-default-insecure-permissions(28445)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "AOL 9.0 Security Edition revision 4184.2340, and probably other versions, uses insecure permissions (Everyone/Full Control) for the \"America Online 9.0\" directory, which allows local users to gain privileges by replacing critical files."
        }, {
          "lang" : "en",
          "value" : "AOL has released fixes to address this issue. These fixes can be automatically applied by logging in to the service."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:aol:aol:9.0_4184.2340:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.2
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 3.9,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-08-21T18:04Z",
    "lastModifiedDate" : "2018-10-18T16:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0949",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "raidenhttpd",
            "product" : {
              "product_data" : [ {
                "product_name" : "raidenhttpd",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.1.47",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/19032",
          "name" : "19032",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/secunia_research/2006-15/advisory/",
          "name" : "http://secunia.com/secunia_research/2006-15/advisory/",
          "refsource" : "MISC",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/23616",
          "name" : "23616",
          "refsource" : "OSVDB",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16934",
          "name" : "16934",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0807",
          "name" : "ADV-2006-0807",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/25037",
          "name" : "raidenhttpd-extension-obtain-information(25037)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "RaidenHTTPD 1.1.47 allows remote attackers to obtain source code of script files, including PHP, via crafted requests involving (1) \".\" (dot), (2) space, and (3) \"/\" (slash) characters."
        }, {
          "lang" : "en",
          "value" : "This vulnerability affects RaidenHTTPD, RaidenHTTPD version 1.1.47 and may affect all previous versions."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:raidenhttpd:raidenhttpd:1.1.47:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-03-06T21:02Z",
    "lastModifiedDate" : "2017-07-20T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0950",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "unalz",
            "product" : {
              "product_data" : [ {
                "product_name" : "unalz",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.53",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-22"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://marc.info/?l=full-disclosure&m=114226632422033&w=2",
          "name" : "20060313 Secunia Research: unalz Filename Handling",
          "refsource" : "FULLDISC",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/19063",
          "name" : "19063",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/secunia_research/2006-16/",
          "name" : "http://secunia.com/secunia_research/2006-16/",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://securityreason.com/securityalert/575",
          "name" : "575",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://securitytracker.com/id?1015780",
          "name" : "1015780",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/23835",
          "name" : "23835",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/427475/100/0/threaded",
          "name" : "20060313 Secunia Research: unalz Filename Handling Directory TraversalVulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/17105",
          "name" : "17105",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0938",
          "name" : "ADV-2006-0938",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/25171",
          "name" : "unalz-archive-directory-traversal(25171)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "unalz 0.53 allows user-assisted attackers to overwrite arbitrary files via an ALZ archive with \"..\" (dot dot) sequences in a filename."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:unalz:unalz:0.53:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:H/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "HIGH",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 2.6
        },
        "severity" : "LOW",
        "exploitabilityScore" : 4.9,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2006-03-13T19:34Z",
    "lastModifiedDate" : "2018-10-18T16:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0951",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "eset_software",
            "product" : {
              "product_data" : [ {
                "product_name" : "nod32_antivirus",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.5",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/19054",
          "name" : "19054",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/secunia_research/2006-17/advisory/",
          "name" : "http://secunia.com/secunia_research/2006-17/advisory/",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/24394",
          "name" : "24394",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/1242",
          "name" : "ADV-2006-1242",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The GUI (nod32.exe) in NOD32 2.5 runs with SYSTEM privileges when the scheduler runs a scheduled on-demand scan, which allows local users to execute arbitrary code during a scheduled scan via unspecified attack vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:eset_software:nod32_antivirus:2.5:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.2
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 3.9,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-04-08T01:04Z",
    "lastModifiedDate" : "2011-03-08T02:31Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0956",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "nufw",
            "product" : {
              "product_data" : [ {
                "product_name" : "nufw_firewall",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0.20",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/19046",
          "name" : "19046",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.nufw.org/+NuFW-1-21-minor-security-fix+.html",
          "name" : "http://www.nufw.org/+NuFW-1-21-minor-security-fix+.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16868",
          "name" : "16868",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0762",
          "name" : "ADV-2006-0762",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "nuauth in NuFW before 1.0.21 does not properly handle blocking TLS sockets, which allows remote authenticated users to cause a denial of service (service hang) by flooding packets at the authentication server."
        }, {
          "lang" : "en",
          "value" : "This vulnerability affects NuFW, NuFW Firewall versions 1.0.20 and previous."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:nufw:nufw_firewall:1.0.20:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:S/C:N/I:N/A:P",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 1.7
        },
        "severity" : "LOW",
        "exploitabilityScore" : 3.1,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-03-02T23:02Z",
    "lastModifiedDate" : "2011-03-08T02:31Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0957",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "zoneo-soft",
            "product" : {
              "product_data" : [ {
                "product_name" : "freeforum",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://evuln.com/vulns/89/summary.html",
          "name" : "http://evuln.com/vulns/89/summary.html",
          "refsource" : "MISC",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/19020",
          "name" : "19020",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://soft.zoneo.net/freeForum/changes.php",
          "name" : "http://soft.zoneo.net/freeForum/changes.php",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/427321/100/0/threaded",
          "name" : "20060310 [eVuln] FreeForum PHP Code Execution & Multiple XSS Vulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16871",
          "name" : "16871",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0759",
          "name" : "ADV-2006-0759",
          "refsource" : "VUPEN",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Direct static code injection vulnerability in func.inc.php in ZoneO-Soft freeForum before 1.2.1 allows remote attackers to execute arbitrary PHP code via the (1) X-Forwarded-For and (2) Client-Ip HTTP headers, which are stored in Data/flood.db.php."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:zoneo-soft:freeforum:1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:zoneo-soft:freeforum:1.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:zoneo-soft:freeforum:1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:zoneo-soft:freeforum:1.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:zoneo-soft:freeforum:1.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:zoneo-soft:freeforum:1.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-03-02T23:02Z",
    "lastModifiedDate" : "2018-10-18T16:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0958",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "zoneo-soft",
            "product" : {
              "product_data" : [ {
                "product_name" : "freeforum",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://evuln.com/vulns/89/summary.html",
          "name" : "http://evuln.com/vulns/89/summary.html",
          "refsource" : "MISC",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://secunia.com/advisories/19020",
          "name" : "19020",
          "refsource" : "SECUNIA",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://soft.zoneo.net/freeForum/changes.php",
          "name" : "http://soft.zoneo.net/freeForum/changes.php",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/427321/100/0/threaded",
          "name" : "20060310 [eVuln] FreeForum PHP Code Execution & Multiple XSS Vulnerabilities",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16877",
          "name" : "16877",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0759",
          "name" : "ADV-2006-0759",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24925",
          "name" : "freeforum-func-xss(24925)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in func.inc.php in ZoneO-Soft freeForum before 1.2.1 allows remote attackers to inject arbitrary web script or HTML via the (1) name and (2) subject parameters."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:zoneo-soft:freeforum:1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:zoneo-soft:freeforum:1.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:zoneo-soft:freeforum:1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:zoneo-soft:freeforum:1.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:zoneo-soft:freeforum:1.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:zoneo-soft:freeforum:1.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-03-02T23:02Z",
    "lastModifiedDate" : "2018-10-18T16:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0959",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "mybulletinboard",
            "product" : {
              "product_data" : [ {
                "product_name" : "mybulletinboard",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.4",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/19061",
          "name" : "19061",
          "refsource" : "SECUNIA",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://securityreason.com/securityalert/512",
          "name" : "512",
          "refsource" : "SREASON",
          "tags" : [ ]
        }, {
          "url" : "http://www.osvdb.org/23554",
          "name" : "23554",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/426320/100/0/threaded",
          "name" : "20060228 MyBB 1.3 NewSQL Injection",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/426653/100/0/threaded",
          "name" : "20060303 MyBB 1.04 Perl Exploit",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16631",
          "name" : "16631",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0774",
          "name" : "ADV-2006-0774",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24953",
          "name" : "mybb-misc-sql-injection(24953)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/1539",
          "name" : "1539",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in misc.php in MyBulletinBoard (MyBB) 1.03, when register_globals is enabled, allows remote attackers to execute arbitrary SQL commands by setting the comma variable value via the comma parameter in a cookie.  NOTE: 1.04 has also been reported to be affected."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mybulletinboard:mybulletinboard:1.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mybulletinboard:mybulletinboard:1.0.4:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-03-02T23:02Z",
    "lastModifiedDate" : "2018-10-18T16:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0960",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "compex",
            "product" : {
              "product_data" : [ {
                "product_name" : "netpassage_wpe54g",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/19037",
          "name" : "19037",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1015690",
          "name" : "1015690",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.security.nnov.ru/Ldocument605.html",
          "name" : "http://www.security.nnov.ru/Ldocument605.html",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16894",
          "name" : "16894",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0780",
          "name" : "ADV-2006-0780",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24968",
          "name" : "netpassage-udp-dos(24968)",
          "refsource" : "XF",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "uConfig agent in Compex NetPassage WPE54G router allows remote attackers to cause a denial of service (unresposiveness) via crafted datagrams to UDP port 7778."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:h:compex:netpassage_wpe54g:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-03-02T23:02Z",
    "lastModifiedDate" : "2017-07-20T01:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0961",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "cilem",
            "product" : {
              "product_data" : [ {
                "product_name" : "cilem_haber",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://archives.neohapsis.com/archives/bugtraq/2006-02/0449.html",
          "name" : "20060224 Advisory: CilemNews System <= 1.1 Remote SQL Injection Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://marc.info/?l=full-disclosure&m=114079912721723&w=2",
          "name" : "20060224 Advisory: CilemNews System <= 1.1 Remote SQL",
          "refsource" : "FULLDISC",
          "tags" : [ ]
        }, {
          "url" : "http://secunia.com/advisories/19157",
          "name" : "19157",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://securitytracker.com/id?1015677",
          "name" : "1015677",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.nukedx.com/?viewdoc=10",
          "name" : "http://www.nukedx.com/?viewdoc=10",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        }, {
          "url" : "http://www.osvdb.org/23618",
          "name" : "23618",
          "refsource" : "OSVDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16813",
          "name" : "16813",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0881",
          "name" : "ADV-2006-0881",
          "refsource" : "VUPEN",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24920",
          "name" : "cilemnews-sql-injection(24920)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/1562",
          "name" : "1562",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in yazdir.asp in Cilem Hiber 1.1 allows remote attackers to execute arbitrary SQL commands via the haber_id parameter.  NOTE: this product has also been referred to as \"Cilem News,\" although that does not appear to be the proper name."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cilem:cilem_haber:1.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-03-02T23:02Z",
    "lastModifiedDate" : "2017-10-19T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0962",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "vubb",
            "product" : {
              "product_data" : [ {
                "product_name" : "vubb",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://secunia.com/advisories/19084",
          "name" : "19084",
          "refsource" : "SECUNIA",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/16930",
          "name" : "16930",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.vupen.com/english/advisories/2006/0799",
          "name" : "ADV-2006-0799",
          "refsource" : "VUPEN",
          "tags" : [ ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/25019",
          "name" : "vubb-index-sql-injection(25019)",
          "refsource" : "XF",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/1543",
          "name" : "1543",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in vuBB 0.2 allows remote attackers to execute arbitrary SQL commands via the pass parameter in a cookie."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:vubb:vubb:0.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : true,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2006-03-02T23:02Z",
    "lastModifiedDate" : "2017-10-19T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2006-0963",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "stlport",
            "product" : {
             